首页> 外文期刊>Computer networks >Secure Multi-Cloud Network Virtualization
【24h】

Secure Multi-Cloud Network Virtualization

机译:安全的多云网络虚拟化

获取原文
获取原文并翻译 | 示例

摘要

Existing network virtualization systems share a few characteristics, namely they target one data center of a single operator and only offer traditional networking services. As such, their support for critical applications that need to be deployed across multiple trust domains, while enforcing diverse security requirements, is limited. This paper enhances the state-of-the-art by presenting a multi-cloud network virtualization system, allowing the provision of virtual networks of containers. Our solution enables a provider to enrich its network substrate with public and private cloud-based resources, increasing flexibility and the range of supplied services. One challenging aspect that we tackle is the embedding of virtual network requests to the substrate infrastructure, as existing work is unfit to a modern data center context, scales poorly or does not consider the security of virtual resources. We propose a scalable heuristic that considers security as a first-class citizen and is specifically tailored to a hybrid multi-cloud domain. We evaluate our algorithm with large-scale simulations that consider realistic network topologies and our prototype in a substrate composed of one private data center and two public clouds. The system scales well for networks of thousands of switches employing diverse topologies and improves on the virtual network acceptance ratio, provider revenue, and embedding delays. Our results show that the acceptance ratios are less than 1% from the optimal and that the system can provision a 10 thousand container virtual network in approximately 2 minutes. (C) 2019 Elsevier B.V. All rights reserved.
机译:现有的网络虚拟化系统具有一些特征,即它们以单个运营商的一个数据中心为目标,并且仅提供传统的网络服务。因此,它们对需要在多个信任域之间部署的关键应用程序的支持有限,同时又执行各种安全要求。本文通过介绍一种多云网络虚拟化系统来增强最新技术,从而允许提供容器的虚拟网络。我们的解决方案使提供商能够利用基于公共和私有云的资源来丰富其网络基础,从而增加灵活性和所提供服务的范围。我们要解决的一个具有挑战性的方面是将虚拟网络请求嵌入到基础结构中,因为现有工作不适合现代数据中心环境,扩展性差或不考虑虚拟资源的安全性。我们提出了一种可扩展的启发式方法,该方法将安全性视为一等公民,并且专门针对混合多云域而量身定制。我们通过考虑实际网络拓扑的大规模仿真评估我们的算法,并在由一个私有数据中心和两个公共云组成的基板中对我们的原型进行评估。该系统可很好地扩展到采用各种拓扑的数千个交换机的网络,并改善虚拟网络的接受率,提供商收入和嵌入延迟。我们的结果表明,接受率与最佳值相比不到1%,并且该系统可以在大约2分钟内提供一个10,000个容器虚拟网络。 (C)2019 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号