【24h】

Size-based flow management prototype for dynamic DMZ

机译:动态DMZ的基于大小的流管理原型

获取原文

摘要

The dynamic demilitarized zone (DMZ) model considers both network performance and security, and dynamically responds to traffic demands in real-time. We realize this dynamic DMZ model based on an OpenFlow-enabled switch and controller. In our approach, the controller detects flows with bit rate greater than a given threshold (elephant flows) and controls the switch in order to reroute elephant flows bypassing the security device. Extensive experiments are performed to verify the feasibility of this approach and test how the threshold value influences network performance. Results indicate that our approach effectively increases network performance but does not significantly influence flow security. Finally, we perform theoretical calculation on the deep packet inspection (DPI) input data rate in order to guide selection of the threshold value with a given traffic flow distribution and maximum DPI processing rate.
机译:动态非军事区(DMZ)模型同时考虑了网络性能和安全性,并实时动态响应流量需求。我们基于启用了OpenFlow的交换机和控制器来实现这种动态DMZ模型。在我们的方法中,控制器检测到比特率大于给定阈值的流(大象流)并控制交换机,以绕过安全设备重新路由大象流。进行了广泛的实验,以验证这种方法的可行性,并测试阈值如何影响网络性能。结果表明,我们的方法可以有效地提高网络性能,但不会显着影响流量安全性。最后,我们对深度包检查(DPI)输入数据速率进行理论计算,以指导在给定流量分配和最大DPI处理速率的情况下选择阈值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号