透過您的圖書館登入
IP:18.221.165.246
  • 學位論文

以多重通訊協定標籤交換傳輸為基礎解決中間件服務鏈佈署於軟體定義網路中之問題

Using MPLS Based Solution for Middlebox Policy Enforcement in Software Defined Network

指導教授 : 周承復

摘要


中間件在軟體定義網路中扮演重要的角色,可以協助提供網路安全及提升網路傳輸效能等。在軟體定義網路中,控制層需有整個網路的全局資訊以便作路由決策,然而中間件在提供額外的服務時,往往不會將內部對資料流所作的處理方法公開出來,因此當資料流經中間件後,控制層喪失了此資料流完整的資訊,無法對此資料流作路由決策。此外,網路架構中中間件數量龐大,根據研究顯示,中間件的擺放位置會造成資料層下網路設備的路由表有迴圈的情形發生。我們提出了名為FastLabel的架構,此架構以多重通訊協定標籤交換傳輸(Multi-Protocol Label Switching,縮寫為MPLS)為基礎的方式,並額外在封包的VLAN標頭中嵌入特定標籤,在不用改動到中間件及現有的網路設備下,讓控制層能夠得知中間件不願公開的內部規則,並同時解決中間件所造成的路由迴圈問題,讓控制層對每個資料流從發出端到接送端整個路徑上所經過的處理都能完全的掌控,能夠因此下達正確的路由決策。實驗結果顯示,我們的方法在路由決策設定完成的時間能夠比其他方法快約37%,同時不會造成控制層與中間件過大的負擔。

並列摘要


Middleboxes play a critical role in software defined network (SDN) to ensure network security and to reduce network transmission overhead. A controller in SDN needs whole network information for inserting right forwarding rules in switches. However, due to the proprietary nature of middleboxes, a SDN controller may have limited visibility to set up forwarding rules that account for intern transformations of middleboxes. Besides, surveys show that the placement of middleboxes may cause conflicting rules in switches.In response we develop a FastLabel architecture. FastLabel is an tagging method based on MPLS which is used to forward packets and find inter transformations middleboxes want to hide. In addition, we insert a tag into VLAN field for solving conflicted rules caused by the placements of middleboxes. Our method makes controller know whole network information without modifying middleboxes and switches. The experiment shows that our method is 34% faster than other works for inserting forwarding rules into switches, less controller overhead and less middlebox overhead.

參考文獻


[16] V. Sekar, S. Ratnasamy, M. K. Reiter, N. Egi, and G. Shi. The middlebox manifesto: enabling innovation in middlebox deployment. In Proceedings of the 10th ACM Workshop on Hot Topics in Networks, page 21. ACM, 2011.
[5] S. K. Fayazbakhsh, L. Chiang, V. Sekar, M. Yu, and J. C. Mogul. Enforcing networkwide policies in the presence of dynamic middlebox actions using flowtags. In 11th USENIX Symposium on Networked Systems Design and Implementation (NSDI 14), pages 543–546, 2014.
[7] A. Gember, A. Krishnamurthy, S. S. John, R. Grandl, X. Gao, A. Anand, T. Benson, V. Sekar, and A. Akella. Stratos: A network-aware orchestration layer for virtual middleboxes in clouds. arXiv preprint arXiv:1305.0209, 2013.
[6] A. Feldmann, A. Greenberg, C. Lund, N. Reingold, J. Rexford, and F. True. Deriving traffic demands for operational ip networks: Methodology and experience. IEEE/ACM Transactions on Networking (ToN), 9(3):265–280, 2001.
[9] P. Gill, N. Jain, and N. Nagappan. Understanding network failures in data centers: measurement, analysis, and implications. In ACM SIGCOMM Computer Communication Review, volume 41, pages 350–361. ACM, 2011.

延伸閱讀