Secure and Reliable Network Updates

Secure and Reliable Network Updates
复制标题

安全可靠的网络更新

DOI:
10.1145/3556542
复制
发表时间:
2023
影响因子:
2.3
通讯作者:
Eugster, Patrick
Eugster, Patrick
中科院分区:
计算机科学4区
文献类型:
--
作者:
Lembke, James;Ravi, Srivatsan;Roman, Pierre-Louis;Eugster, Patrick

文献摘要

参考文献

被引文献

相似文献

软件定义的广域网络(SD-WAN)可通过网络更新实现对大型分布式网络的动态网络策略控制。为了实用,网络更新必须是一致的(即,没有更新到多个交换机导致的瞬时错误)、安全(即,仅当从有效控制器发送时才执行)和可靠(即,在控制平面中存在故障或恶意成员的情况下仍可运行),同时仅对控制器和交换机施加最小的开销。简而言之:一致性是通过组合更新调度程序和分布式事务协议来提供的。通过对网络事件和更新进行身份验证来保护安全性,后者使用自适应阈值加密方案。可靠性是通过复制控制平面并通过使用分布式分类帐作为控制器故障检测器来使其对动态对手具有弹性来提供的。我们通过定义独立的网络域并利用域内和域间网络更新的并行性来提供可伸缩性机制,从而确保实用性。我们形式化地定义了Serene协议,并从事件线性化的角度证明了其安全性。广泛的实验表明,Serene施加的交换机负担最小,并且可以扩展到运行多个网络应用的大型网络,这些应用都需要并发网络更新,最坏情况下,短期流完成会带来16%的开销,而预期的正常工作负载的开销可以忽略不计。
Software-defined wide area networking (SD-WAN) enables dynamic network policy control over a large distributed network vianetwork updates. To be practical, network updates must be consistent (i.e., free of transient errors caused by updates to multiple switches), secure (i.e., only be executed when sent from valid controllers), and reliable (i.e., function despite the presence of faulty or malicious members in the control plane), while imposing only minimal overhead on controllers and switches.We present SERENE: a protocol forsecure andreliablenetwork updates for SD-WAN environments. In short: Consistency is provided through the combination of an update scheduler and a distributed transactional protocol. Security is preserved by authenticating network events and updates, the latter with an adaptive threshold cryptographic scheme. Reliability is provided by replicating the control plane and making it resilient to a dynamic adversary by using a distributed ledger as a controller failure detector. We ensure practicality by providing a mechanism for scalability through the definition of independent network domains and exploiting the parallelism of network updates both within and across domains. We formally define SERENE’s protocol and prove its safety with regards to event-linearizability. Extensive experiments show that SERENE imposes minimal switch burden and scales to large networks running multiple network applications all requiring concurrent network updates, imposing at worst a 16% overhead on short-lived flow completion and negligible overhead on anticipated normal workloads.
soFTDP:安全高效的OpenFlow拓扑发现协议
DOI: 10.1109/noms.2018.8406229
发表时间: 2017
期刊: NOMS 2018 - 2018 IEEE/IFIP Network Operations and Management Symposium
影响因子: --
作者:
A. Azzouni;R. Boutaba;T. Nguyen;G. Pujolle
通讯作者: G. Pujolle
DOI: 10.1145/1294261.1294279
发表时间: 2007-10
期刊: --
影响因子: --
作者:
Andreas Haeberlen;P. Kuznetsov;P. Druschel
通讯作者: Andreas Haeberlen;P. Kuznetsov;P. Druschel
用于定位 SDN 数据平面中行为不当源的虚拟化网络视图
DOI: 10.1109/icc.2017.7997296
发表时间: 2017
期刊: 2017 IEEE International Conference on Communications (ICC)
影响因子: --
作者:
Maha Shamseddine;W. Itani;A. Kayssi;A. Chehab
通讯作者: A. Chehab
DOI: 10.1145/359168.359176
发表时间: 1979-01-01
影响因子: 22.7
作者:
SHAMIR, A
通讯作者: SHAMIR, A
分布式SDN控制平面一致数据存储的设计与实现
DOI: 10.1109/edcc.2016.12
发表时间: 2016
期刊: 2016 12th European Dependable Computing Conference (EDCC)
影响因子: --
作者:
F. Botelho;T. A. Ribeiro;P. Ferreira;Fernando M. V. Ramos;A. Bessani
通讯作者: A. Bessani