BigMaC: Reactive Network-Wide Policy Caching for SDN Policy Enforcement

被引:10
|
作者
Yan, Bo [1 ]
Xu, Yang [1 ]
Chao, H. Jonathan [1 ]
机构
[1] NYU, Tandon Sch Engn, Dept Elect & Comp Engn, Brooklyn, NY 11201 USA
基金
美国国家科学基金会;
关键词
SDN; network-wide policy caching; policy enforcement; MANAGEMENT;
D O I
10.1109/JSAC.2018.2871296
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Enforcing network policies is critical for service deployments over software-defined networks (SDN). Most existing studies suggest proactively compiling policies into flow entries in the data plane and updating the installed entries when necessary. With a growing amount of applications, taking a proactive approach may overflow underlying switch memory. Meanwhile, certain policies can be frequently updated. Such updates may propagate across configurations in the network, leading to a long time for correctness validation. To improve both the scalability and the flexibility of SDN policy enforcement, we advocate reactively deploying network policies in the data plane. To this end, we propose a network-wide policy enforcement framework named BigMaC. BigMaC advertises a neat policy model for network managers to specify various network policies as rules. It then caches the rules as flow entries in the switches reactively on demand. One major challenge for the BigMaC design is to guarantee the consistency of defined policies and cached entries in the network. To maintain consistency with efficient table usage and simple updates, we group rules into buckets and perform rule caching in the unit of buckets. With trace-driven simulations, we verify that BigMaC can significantly save table space and reduce update complexity compared to prior proposals.
引用
收藏
页码:2675 / 2687
页数:13
相关论文
共 50 条
  • [41] SERENIoT: Distributed Network Security Policy Management and Enforcement for Smart Homes
    Thomasset, Corentin
    Barrera, David
    36TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2020), 2020, : 542 - 555
  • [43] Automatic, verifiable and optimized policy-based security enforcement for SDN-aware IoT networks
    Bringhenti, Daniele
    Yusupov, Jalolliddin
    Zarca, Alejandro Molina
    Valenza, Fulvio
    Sisto, Riccardo
    Bernabe, Jorge Bernal
    Skarmeta, Antonio
    COMPUTER NETWORKS, 2022, 213
  • [44] CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships
    Sahay, Rishikesh
    Meng, Weizhi
    Estay, D. A. Sepulveda
    Jensen, Christian D.
    Barfod, Michael Bruhn
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 100 : 736 - 750
  • [45] Usage Control Policy Enforcement in SDN-based Clouds: A Dynamic Availability Service Use Case
    Toumi, Khalifa
    Idrees, Muhammad Sabir
    Charmet, Fabien
    Yaich, Reda
    Blanc, Gregory
    PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 578 - 585
  • [46] Lagrange Multiplier Optimization of the Probabilistic Caching Policy in Noise-Limited Network
    Wang, Sheng-Jie
    Chen, Po-Ning
    Shieh, Shin-Lin
    Huang, Yu-Chih
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2021, 70 (03) : 2684 - 2698
  • [47] Increasing network throughput based on dynamic caching policy at wireless access points
    Jianji Ren
    Tingting Hou
    Haichao Wang
    Hao Ren
    Xiaohong Zhang
    Wireless Networks, 2020, 26 : 1577 - 1585
  • [48] Increasing network throughput based on dynamic caching policy at wireless access points
    Ren, Jianji
    Hou, Tingting
    Wang, Haichao
    Ren, Hao
    Zhang, Xiaohong
    WIRELESS NETWORKS, 2020, 26 (03) : 1577 - 1585
  • [49] Joint Policy for Virtual Network Embedding in Distributed SDN-Enabled Cloud
    Bouchair, Abderrahim
    Yagoubi, Belabbas
    Makhlouf, Sid Ahmed
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (04)
  • [50] Automatic belief network modeling via policy inference for SDN fault localization
    Tang, Yongning
    Cheng, Guang
    Xu, Zhiwei
    Chen, Feng
    Elmansor, Khalid
    Wu, Yangxuan
    JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2016, 7 : 1 - 13