...
首页> 外文期刊>IEEE/ACM Transactions on Networking >vSFC: Generic and Agile Verification of Service Function Chains in the Cloud
【24h】

vSFC: Generic and Agile Verification of Service Function Chains in the Cloud

机译:VSFC:云中服务功能链的通用和敏捷验证

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

With the advent of network function virtualization (NFV), outsourcing network functions (NFs) to the cloud is becoming increasingly popular for enterprises since it brings significant benefits for NF deployment and maintenance, such as improved scalability and reduced overhead. However, NF outsourcing limits the control of customer enterprises over NF deployment and management, consequently raising serious security concerns. Enterprises cannot ensure whether their outsourced NFs and associated service function chains (SFCs) are correctly enforced according to their specifications. In this paper, we propose vSFC, an SFC verification scheme that allows an enterprise to accurately verify the correctness of SFC enforcement in real time. Specifically, it can detect a wide range of SFC violations including forwarding path incompliance, packet dropping, and flow dropping attacks. Meanwhile, it is generic and agile, which can be applied to arbitrary cloud architectures without requiring any modification to NFs. To demonstrate the feasibility and performance of vSFC, we implement a vSFC prototype on top of Linux kernel-based virtual machines (KVM) and conduct extensive experiments with real traffic. The experimental results show that vSFC can accurately detect SFC violations with negligible overhead.
机译:随着网络功能虚拟化(NFV)的出现,外包网络功能(NFS)对企业越来越受欢迎,因为它为NF部署和维护带来了显着的好处,例如改进的可扩展性和减少的开销。但是,NF外包限制了客户企业对NF部署和管理的控制,从而提高了严重的安全问题。企业无法确保他们的外包NFS和相关的服务功能链(SFCS)根据其规格正确强制执行。在本文中,我们提出了VSFC,SFC验证方案,允许企业实时准确地验证证监会执行的正确性。具体来说,它可以检测到各种SFC违规,包括转发路径不合规性,数据包丢弃和流动丢失。同时,它是通用和敏捷的,可以应用于任意云体系结构,而不需要对NFS进行任何修改。为了展示VSFC的可行性和性能,我们在基于Linux内核的虚拟机(KVM)顶部实施了VSFC原型,并通过实际交通进行广泛的实验。实验结果表明,VSFC可以准确地检测SFC违规,其开销可忽略不计。

著录项

  • 来源
    《IEEE/ACM Transactions on Networking》 |2021年第1期|78-91|共14页
  • 作者单位

    Tsinghua Univ Inst Network Sci & Cyberspace Beijing 100084 Peoples R China|Beijing Natl Res Ctr Informat Sci & Technol Beijing 100084 Peoples R China;

    Tsinghua Univ Inst Network Sci & Cyberspace Beijing 100084 Peoples R China|Beijing Natl Res Ctr Informat Sci & Technol Beijing 100084 Peoples R China;

    Tsinghua Univ Inst Network Sci & Cyberspace Beijing 100084 Peoples R China|Beijing Natl Res Ctr Informat Sci & Technol Beijing 100084 Peoples R China;

    Tsinghua Univ Inst Network Sci & Cyberspace Beijing 100084 Peoples R China|Beijing Natl Res Ctr Informat Sci & Technol Beijing 100084 Peoples R China;

    Tsinghua Univ Inst Network Sci & Cyberspace Beijing 100084 Peoples R China|Beijing Natl Res Ctr Informat Sci & Technol Beijing 100084 Peoples R China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Noise measurement; Cloud computing; Switches; Real-time systems; Computer architecture; Software; Service function chain; SFC verification; NFV;

    机译:噪声测量;云计算;切换;实时系统;计算机架构;软件;服务功能链;SFC验证;NFV;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号