首页> 外文会议>IEEE 35th Annual IEEE International Conference on Computer Communications >FOUM: A flow-ordered consistent update mechanism for software-defined networking in adversarial settings
【24h】

FOUM: A flow-ordered consistent update mechanism for software-defined networking in adversarial settings

机译:FOUM:一种按流程排序的一致更新机制,用于对抗环境中的软件定义网络

获取原文
获取原文并翻译 | 示例

摘要

Due to the asynchronous and distributed nature of the data plane, consistent configuration updating across multiple switches is a challenging issue in Software-Defined Networking (SDN). The existing version-stamping-based mechanism (VSM) could guarantee per-packet consistency, but this mechanism is designed for non-adversarial settings and can be compromised easily by a malicious attacker. In this paper, we propose an efficient flow-ordered update mechanism that aims to provide per-packet consistency in adversarial settings. Our proposal does not need to stamp data packets with the configuration version, and is robust against both the packet-tampering and packet-dropping attacks. It outperforms a naive mechanism that simply patches VSM using digital signatures in three aspects: First, the switches in this mechanism only need to sign and verify a single control packet, which significantly improves the packet processing time. Second, it avoids keeping both old and new policies on switches during the update, and thus achieves better space efficiency. Third, it reduces the time delay for new policies to come into force. We evaluate our mechanism on a self-constructed SDN testbed and the results demonstrate high efficiency.
机译:由于数据平面的异步和分布式特性,在多个交换机之间进行一致的配置更新在软件定义网络(SDN)中是一个具有挑战性的问题。现有的基于版本标记的机制(VSM)可以保证每个数据包的一致性,但是该机制是为非对抗性设置而设计的,很容易被恶意攻击者破坏。在本文中,我们提出了一种有效的流有序更新机制,旨在在对抗设置中提供每个数据包的一致性。我们的建议不需要使用配置版本标记数据包,并且对于数据包篡改和数据包丢弃攻击均很可靠。它优于仅在三个方面使用数字签名对VSM进行修补的天真机制:首先,此机制中的交换机仅需要对单个控制数据包进行签名和验证,从而显着缩短了数据包处理时间。其次,它避免了在更新过程中在交换机上同时保留新旧策略,从而提高了空间利用率。第三,它减少了新政策生效的时间延迟。我们在一个自建的SDN测试平台上评估了我们的机制,结果证明了其高效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号