...
首页> 外文期刊>Frontiers of Information Technology & Electronic Engineering >A secure and high-performance multi-controller architecture for software-defined networking
【24h】

A secure and high-performance multi-controller architecture for software-defined networking

机译:用于软件定义网络的安全且高性能的多控制器体系结构

获取原文
           

摘要

Controllers play a critical role in software-defined networking (SDN). However, existing single-controller SDN architectures are vulnerable to single-point failures, where a controller’s capacity can be saturated by flooded flow requests. In addition, due to the complicated interactions between applications and controllers, the flow setup latency is relatively large. To address the above security and performance issues of current SDN controllers, we propose distributed rule store (DRS), a new multi-controller architecture for SDNs. In DRS, the controller caches the flow rules calculated by applications, and distributes these rules to multiple controller instances. Each controller instance holds only a subset of all rules, and periodically checks the consistency of flow rules with each other. Requests from switches are distributed among multiple controllers, in order to mitigate controller capacity saturation attack. At the same time, when rules at one controller are maliciously modified, they can be detected and recovered in time. We implement DRS based on Floodlight and evaluate it with extensive emulation. The results show that DRS can effectively maintain a consistently distributed rule store, and at the same time can achieve a shorter flow setup time and a higher processing throughput, compared with ONOS and Floodlight.
机译:控制器在软件定义网络(SDN)中起着至关重要的作用。但是,现有的单控制器SDN架构易受单点故障的影响,在这种情况下,控制器的容量可能会因洪流请求而饱和。另外,由于应用程序和控制器之间复杂的交互作用,流建立等待时间相对较大。为了解决当前SDN控制器的上述安全性和性能问题,我们提出了分布式规则存储(DRS),这是一种用于SDN的新的多控制器体系结构。在DRS中,控制器缓存由应用程序计算的流规则,并将这些规则分配给多个控制器实例。每个控制器实例仅包含所有规则的子集,并定期检查流规则彼此之间的一致性。来自交换机的请求分布在多个控制器之间,以减轻控制器的容量饱和攻击。同时,如果恶意修改了一个控制器上的规则,则可以及时发现并恢复它们。我们基于Floodlight实施DRS,并通过广泛的仿真对其进行评估。结果表明,与ONOS和Floodlight相比,DRS可以有效维护一致分布的规则存储,同时可以实现更短的流建立时间和更高的处理吞吐量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号