Supporting Diverse Dynamic Intent-based Policies using Janus

Supporting Diverse Dynamic Intent-based Policies using Janus
复制标题

DOI:
10.1145/3143361.3143380
复制
发表时间:
2017-11
期刊:
Proceedings of the 13th International Conference on emerging Networking EXperiments and Technologies
影响因子:
--
通讯作者:
Anubhavnidhi Abhashkumar;Joon-Myung Kang;S. Banerjee;Aditya Akella;Y. Zhang;Wenfei Wu
Anubhavnidhi Abhashkumar;Joon-Myung Kang;S. Banerjee;Aditya Akella;Y. Zhang;Wenfei Wu
中科院分区:
其他
文献类型:
--
作者:
Anubhavnidhi Abhashkumar;Joon-Myung Kang;S. Banerjee;Aditya Akella;Y. Zhang;Wenfei Wu

文献摘要

被引文献

相似文献

现有网络策略抽象处理基于基本组的可达性和基于访问控制列表的安全策略。然而,Qos策略和动态策略也很重要,不在高级策略抽象中表示它们会造成严重的限制。同时,有效地配置和组成基于组的服务质量和动态策略带来了重大的技术挑战,例如(A)在配置期间保持组的粒度,(B)处理来自不同编写器的策略之间的网络带宽竞争,以及(C)处理与动态变化的策略、组成员资格和终端移动性相对应的多个路径变化。在本文中,我们提出了JANUS系统,它有两个主要贡献。首先,我们扩展了先验策略图抽象模型以表示复杂的服务质量和动态的有状态/时态策略。其次,我们将策略配置问题转化为一个优化问题,目标是最大化满足和配置的策略数量,最小化动态环境下的路径变化次数。为了解决这个问题,Janus提出了几种新的启发式算法。我们使用一组不同的带宽策略和网络拓扑来评估我们的系统。我们的实验表明,Janus算法可以在合理的时间内获得近似最优解。
Existing network policy abstractions handle basic group based reachability and access control list based security policies. However, QoS policies as well as dynamic policies are also important and not representing them in the high level policy abstraction poses serious limitations. At the same time, efficiently configuring and composing group based QoS and dynamic policies present significant technical challenges, such as (a) maintaining group granularity during configuration, (b) dealing with network-bandwidth contention among policies from distinct writers and (c) dealing with multiple path changes corresponding to dynamically changing policies, group membership and end-point mobility. In this paper we propose Janus, a system which makes two major contributions. First, we extend the prior policy graph abstraction model to represent complex QoS and dynamic tateful/temporal policies. Second, we convert the policy configuration problem into an optimization problem with the goal of maximizing the number of satisfied and configured policies, and minimizing the number of path changes under dynamic environments. To solve this, Janus presents several novel heuristic algorithms. We evaluate our system using a diverse set of bandwidth policies and network topologies. Our experiments demonstrate that Janus can achieve near-optimal solutions in a reasonable amount of time.