A packet-in message filtering mechanism for protection of control plane in openflow networks

A packet-in message filtering mechanism for protection of control plane in openflow networks
复制标题

DOI:
10.1145/2658260.2658276
复制
发表时间:
2014-10
期刊:
2014 ACM/IEEE Symposium on Architectures for Networking and Communications Systems (ANCS)
影响因子:
--
通讯作者:
Daisuke Kotani;Y. Okabe
Daisuke Kotani;Y. Okabe
中科院分区:
其他
文献类型:
--
作者:
Daisuke Kotani;Y. Okabe

文献摘要

被引文献

相似文献

保护网络硬件中的控制平面免受高速率数据包的影响是运行中网络的一个关键问题。传统网络硬件的一种常见方法是将昂贵的功能卸载到作为 ASIC 的硬连线卸载引擎上。 OpenFlow 网络有望通过数据包转发平面的开放接口和集中控制器提供更大的网络控制灵活性。在 OpenFlow 网络中,仅使用传统网络硬件的方法是不够的,因为它限制了 OpenFlow 预期提供的一定程度的灵活性。因此,我们需要在 OpenFlow 交换机中采用通用的控制平面保护机制作为最后的手段。在本文中,我们提出了一种过滤 Packet-In 消息而不丢失网络控制重要消息的机制。我们提出的机制工作起来很简单。交换机在发送Packet-In报文前记录控制器预先指定的报文头字段值,并过滤掉与记录值相同的报文。我们在原型软件交换机上实现并评估了所提出的机制,得出的结论是,它极大地减少了交换机中的 CPU 负载,并传递重要的 Packet-In 消息以进行网络控制。
Protecting control planes in networking hardware from high rate packets is a critical issue for networks under operation. One common approach for conventional networking hardware is to offload expensive functions onto hard-wired offload engines as ASICs. OpenFlow networks are expected to provide greater network control flexibility by an open interface to the packet-forwarding plane and by centralized controllers. In OpenFlow networks, the approach for conventional networking hardware alone is inadequate because it restricts a certain amount of flexibility that OpenFlow is expected to provide. Therefore, we need a generic control plane protection mechanism in OpenFlow switches as a last resort. In this paper, we propose a mechanism to filter out Packet-In messages without dropping important ones for network control. Our proposed mechanism works simply. Switches record the values of packet header fields before sending Packet-In messages, which are specified by the controllers in advance, and filter out packets that have the same values as the recorded ones. We implemented and evaluated the proposed mechanism on a prototype software switch, concluding that it dramatically reduces CPU loads in the switches and passes important Packet-In messages for network control.