PGA: Using Graphs to Express and Automatically Reconcile Network Policies

PGA: Using Graphs to Express and Automatically Reconcile Network Policies
复制标题

DOI:
10.1145/2785956.2787506
复制
发表时间:
2015-08
期刊:
Proceedings of the 2015 ACM Conference on Special Interest Group on Data Communication
影响因子:
--
通讯作者:
Chaithan Prakash;Jeongkeun Lee;Yoshio Turner;Joon-Myung Kang;Aditya Akella;S. Banerjee;Charles Clark-Charles-Clar
Chaithan Prakash;Jeongkeun Lee;Yoshio Turner;Joon-Myung Kang;Aditya Akella;S. Banerjee;Charles Clark-Charles-Clar
中科院分区:
其他
文献类型:
--
作者:
Chaithan Prakash;Jeongkeun Lee;Yoshio Turner;Joon-Myung Kang;Aditya Akella;S. Banerjee;Charles Clark-Charles-Clar

文献摘要

被引文献

相似文献

软件定义网络(SDN)和云自动化使大量各方(网络运营商、应用管理员、租户/最终用户)和控制程序(SDN应用、网络服务)能够独立和动态地生成网络策略。然而,现有的策略抽象和框架不支持来自不同来源的高级策略的自然表达和自动组合。我们解决了自动、正确、快速地组合多个独立指定的网络策略的未决问题。我们首先开发了一种高级策略图抽象(PGA),它允许简单而独立地表达网络策略,并利用图结构来高效地检测和解决策略冲突。除了支持ACL策略外,PGA还通过将多个服务链需求合并为无冲突的组合链,对服务链策略进行建模和组合,即需要遍历的中间盒序列。我们使用大型企业网络策略数据集进行的系统验证显示,即使对于非常大的输入,实际合成时间也只有亚毫秒级的运行延迟。
Software Defined Networking (SDN) and cloud automation enable a large number of diverse parties (network operators, application admins, tenants/end-users) and control programs (SDN Apps, network services) to generate network policies independently and dynamically. Yet existing policy abstractions and frameworks do not support natural expression and automatic composition of high-level policies from diverse sources. We tackle the open problem of automatic, correct and fast composition of multiple independently specified network policies. We first develop a high-level Policy Graph Abstraction (PGA) that allows network policies to be expressed simply and independently, and leverage the graph structure to detect and resolve policy conflicts efficiently. Besides supporting ACL policies, PGA also models and composes service chaining policies, i.e., the sequence of middleboxes to be traversed, by merging multiple service chain requirements into conflict-free composed chains. Our system validation using a large enterprise network policy dataset demonstrates practical composition times even for very large inputs, with only sub-millisecond runtime latencies.