首页> 外文期刊>Computer communication review >SIMPLE-fying Middlebox Policy Enforcement Using SDN
【24h】

SIMPLE-fying Middlebox Policy Enforcement Using SDN

机译:使用SDN轻松执行中间盒策略

获取原文
获取原文并翻译 | 示例
           

摘要

Networks today rely on middleboxes to provide critical performance, security, and policy compliance capabilities. Achieving these benefits and ensuring that the traffic is directed through the desired sequence of middleboxes requires significant manual effort and operator expertise. In this respect, Software-Defined Networking (SDN) offers a promising alternative. Middleboxes, however, introduce new aspects (e.g., policy composition, resource management, packet modifications) that fall outside the purvey of traditional L2/L3 functions that SDN supports (e.g., access control or routing). This paper presents SIMPLE, a SDN-based policy enforcement layer for efficient middlebox-specific "traffic steering". In designing SIMPLE, we take an explicit stance to work within the constraints of legacy middleboxes and existing SDN interfaces. To this end, we address algorithmic and system design challenges to demonstrate the feasibility of using SDN to simplify middlebox traffic steering. In doing so, we also take a significant step toward addressing industry concerns surrounding the ability of SDN to integrate with existing infrastructure and support L4-L7 capabilities.
机译:当今的网络依靠中间盒来提供关键的性能,安全性和策略合规性功能。要获得这些好处并确保通过所需的中间盒序列引导流量,需要大量的人工和操作员的专业知识。在这方面,软件定义网络(SDN)提供了有希望的替代方案。但是,中间盒引入了SDN支持的传统L2 / L3功能(例如访问控制或路由)所无法提供的新方面(例如,策略组成,资源管理,数据包修改)。本文介绍了SIMPLE,这是一个基于SDN的策略执行层,用于高效的特定于中间盒的“流量控制”。在设计SIMPLE时,我们采取了明确的立场,以在传统中间盒和现有SDN接口的约束下工作。为此,我们解决了算法和系统设计难题,以证明使用SDN简化中间盒流量控制的可行性。在此过程中,我们还朝着解决业界对SDN与现有基础架构集成和支持L4-L7功能的能力的关注迈出了重要的一步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号