ClassBench-ng: Benchmarking Packet Classification Algorithms in the OpenFlow Era

ClassBench-ng: Benchmarking Packet Classification Algorithms in the OpenFlow Era
复制标题

DOI:
10.1109/tnet.2022.3155708
复制
发表时间:
2022-10
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
J. Matoušek;Adam Lucanský;David Janecek;Jozef Sabo;J. Korenek;G. Antichi
J. Matoušek;Adam Lucanský;David Janecek;Jozef Sabo;J. Korenek;G. Antichi
中科院分区:
其他
文献类型:
--
作者:
J. Matoušek;Adam Lucanský;David Janecek;Jozef Sabo;J. Korenek;G. Antichi

文献摘要

相似文献

分组分类,即,将分组分类为流的过程是任何联网设备中的头等公民。每次必须处理新数据包时,都需要将一个或多个报头字段与一组预先安装的规则进行比较。这是为基本的转发操作而做的,以应用安全策略、特定于应用程序的处理或服务质量保证。大量的研究工作已经确定了更好的查找技术,即,通过利用规则集特征,找到分组报头和规则之间的最佳匹配。在这里,ClassBench通过支持IPv4规则集的生成为社区提供了极大的服务。在本文中,我们提出了一个新的工具,ClassBench-ng,创建合成IPv4,IPv6和OpenFlow规则。我们从分析部署在野外的分类规则开始,并使用这些发现来制定我们的解决方案。ClassBench-ng可以生成用户定义数量的规则以及与之匹配的关联头跟踪。与最先进的解决方案相比,规则集生成过程通常更准确,并且能够生成与许多不同用例匹配的规则,即,从IPv4路由器到OpenFlow交换机,这在当前的规则集生成工具中是唯一的。
Packet classification, i.e., the process of categorizing packets into flows, is a first-class citizen in any networking device. Every time a new packet has to be processed, one or more header fields need to be compared against a set of pre-installed rules. This is done for basic forwarding operations, to apply security policies, application-specific processing, or quality-of-service guarantees. A lot of research efforts have identified better lookup techniques, i.e., finding the best match between packet headers and rules, by capitalizing on the rule sets characteristics. Here, ClassBench has greatly served the community by enabling the generation of IPv4 rule sets. In this paper, we present a new tool, ClassBench-ng, that creates synthetic IPv4, IPv6, and OpenFlow rules. We start from an analysis of classification rules deployed in-the-wild and we use the findings to craft our solution. ClassBench-ng can generate a user-defined number of rules as well as an associated header trace matching them. Compared to state-of-the-art solutions, the rule set generation process is usually more accurate and it is able to produce rules matching a number of different use cases, i.e., from an IPv4 router to an OpenFlow switch, which is unique among current rule set generation tools.