首页> 外文会议>Australasian conference on information security and privacy >DOCSDN: Dynamic and Optimal Configuration of Software-Defined Networks
【24h】

DOCSDN: Dynamic and Optimal Configuration of Software-Defined Networks

机译:DOCSDN:软件定义网络的动态和最佳配置

获取原文

摘要

Networks are designed with functionality, security, performance, and cost in mind. Tools exist to check or optimize individual properties of a network. These properties may conflict, so it is not always possible to run these tools in series to find a configuration that meets all requirements. This leads to network administrators manually searching for a configuration. This need not be the case. In this paper, we introduce a layered framework for optimizing network configuration for functional and security requirements. Our framework is able to output configurations that meet reachability, bandwidth, and risk requirements. Each layer of our framework optimizes over a single property. A lower layer can constrain the search problem of a higher layer allowing the framework to converge on a joint solution. Our approach has the most promise for software-defined networks which can easily reconfigure their logical configuration. Our approach is validated with experiments over the fat tree topology, which is commonly used in data center networks. Search terminates in between 1-5 min in experiments. Thus, our solution can propose new configurations for short term events such as defending against a focused network attack.
机译:网络的设计考虑了功能,安全性,性能和成本。存在用于检查或优化网络的各个属性的工具。这些属性可能会发生冲突,因此并非总是可以连续运行这些工具来找到满足所有要求的配置。这导致网络管理员手动搜索配置。不必是这种情况。在本文中,我们介绍了一个分层的框架,用于针对功能和安全要求优化网络配置。我们的框架能够输出满足可达性,带宽和风险要求的配置。我们框架的每一层都在单个属性上进行优化。较低的层可以约束较高层的搜索问题,从而允许框架收敛在联合解决方案上。对于可以轻松地重新配置其逻辑配置的软件定义网络,我们的方法最有前途。我们的方法已通过在数据中心网络中常用的胖树拓扑的实验得到验证。在实验中,搜索会在1-5分钟之间终止。因此,我们的解决方案可以针对短期事件(例如防御有针对性的网络攻击)提出新的配置。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号