首页> 外文期刊>Computer networks >An efficient architecture for dynamic middlebox policy enforcement in SDN networks
【24h】

An efficient architecture for dynamic middlebox policy enforcement in SDN networks

机译:用于SDN网络中动态中间盒策略实施的有效架构

获取原文
获取原文并翻译 | 示例
       

摘要

Middleboxes are widely deployed devices that play crucial roles in today's networks. Their behavior is commonly determined by policies that are manually set by network administrators, what may be a burden for networks whose connectivity dynamically changes. Recently, with the advent of Software-Defined Networking (SDN), a number of possibilities for handling middlebox policy enforcement have emerged. Even though there have been some contributions in this area, none of them eliminate the necessity of manual configuration of middleboxes for policy enforcement. In this paper, we propose an SDN-based architecture for dynamic middlebox policy enforcement that is able to respond to network events without any manual intervention from the network administrator. The architecture is also based on an interface proposed in this paper that enables the communication between an SDN controller and any middlebox. To evaluate the policy enforcement architecture, a prototype with two types of middleboxes, a firewall and an Intrusion Prevention System (IPS), was implemented in a virtual machine. Hypothesis tests were performed in order to validate the experimental results obtained with the prototype. Results show that the architecture is able to dynamically enforce middlebox policies, allowing network applications to run appropriately with no impact on network performance. (C) 2017 Elsevier B.V. All rights reserved.
机译:中间盒是广泛部署的设备,在当今的网络中起着至关重要的作用。它们的行为通常由网络管理员手动设置的策略确定,这可能会对连接性动态变化的网络造成负担。最近,随着软件定义网络(SDN)的出现,出现了许多处理中间盒策略实施的可能性。即使在此领域做出了一些贡献,但它们都没有消除手动配置中间盒以执行策略的必要性。在本文中,我们提出了一种用于动态中间盒策略实施的基于SDN的体系结构,该体系结构能够响应网络事件,而无需网络管理员的任何手动干预。该架构还基于本文提出的接口,该接口支持SDN控制器与任何中间盒之间的通信。为了评估策略实施体系结构,在虚拟机中实现了具有两种类型的中间盒,防火墙和入侵防御系统(IPS)的原型。为了验证通过原型获得的实验结果,进行了假设检验。结果表明,该体系结构能够动态实施中间盒策略,从而允许网络应用程序正常运行,而不会影响网络性能。 (C)2017 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号