Efficient querying and maintenance of network provenance at internet-scale

Efficient querying and maintenance of network provenance at internet-scale
复制标题

DOI:
10.1145/1807167.1807234
复制
发表时间:
2010-06
期刊:
Proceedings of the 2010 ACM SIGMOD International Conference on Management of data
影响因子:
--
通讯作者:
Wenchao Zhou;M. Sherr;Tao Tao-Tao;Xiaozhou Li;B. T. Loo;Yun Mao
Wenchao Zhou;M. Sherr;Tao Tao-Tao;Xiaozhou Li;B. T. Loo;Yun Mao
中科院分区:
其他
文献类型:
--
作者:
Wenchao Zhou;M. Sherr;Tao Tao-Tao;Xiaozhou Li;B. T. Loo;Yun Mao

文献摘要

被引文献

相似文献

网络问责制、取证分析和故障诊断对于网络管理和安全变得越来越重要。这种能力通常利用网络起源-通过网络元数据发出查询的能力。例如,网络起源可以用于跟踪消息在网络上遍历的路径,以及确定消息数据是如何导出的以及消息数据的导出涉及哪些方。本文介绍了ExSPAN的设计和实现,一个通用的和可扩展的框架,实现高效的网络起源在分布式环境中。我们利用数据起源的数据库概念来“解释”任何网络状态的存在,为网络起源提供了一个通用的机制。为了在互联网范围内实现这种灵活性,ExSPAN使用声明式网络,其中网络协议可以建模为分布式流上的连续查询,并在声明式查询语言中简洁地指定。我们扩展了现有的数据库文献中开发的数据模型的出处,使分布在互联网规模,并研究了许多优化技术,以有效地维护和查询分布式网络出处。ExSPAN原型是使用RapidNet开发的,RapidNet是一个基于新兴ns-3工具包的声明式网络平台。在模拟网络和实际部署的测试平台环境中的实验表明,我们的系统支持广泛的分布式出处计算效率,从而显着降低带宽成本相比,传统的方法。
Network accountability, forensic analysis, and failure diagnosis are becoming increasingly important for network management and security. Such capabilities often utilize network provenance - the ability to issue queries over network meta-data. For example, network provenance may be used to trace the path a message traverses on the network as well as to determine how message data were derived and which parties were involved in its derivation. This paper presents the design and implementation of ExSPAN, a generic and extensible framework that achieves efficient network provenance in a distributed environment. We utilize the database notion of data provenance to "explain" the existence of any network state, providing a versatile mechanism for network provenance. To achieve such flexibility at Internet-scale, ExSPAN uses declarative networking in which network protocols can be modeled as continuous queries over distributed streams and specified concisely in a declarative query language. We extend existing data models for provenance developed in database literature to enable distribution at Internet-scale, and investigate numerous optimization techniques to maintain and query distributed network provenance efficiently. The ExSPAN prototype is developed using RapidNet, a declarative networking platform based on the emerging ns-3 toolkit. Experiments over a simulated network and an actual deployment in a testbed environment demonstrate that our system supports a wide range of distributed provenance computations efficiently, resulting in significant reductions in bandwidth costs compared to traditional approaches.