PACE: Policy-Aware Application Cloud Embedding

PACE: Policy-Aware Application Cloud Embedding
复制标题

DOI:
10.1109/infcom.2013.6566849
复制
发表时间:
2013-04
期刊:
2013 Proceedings IEEE INFOCOM
影响因子:
--
通讯作者:
Erran L. Li;Vahid Liaghat;Hongze Zhao;M. Hajiaghayi;Dan Li;G. Wilfong;Y. Yang;Chuanxiong Guo
Erran L. Li;Vahid Liaghat;Hongze Zhao;M. Hajiaghayi;Dan Li;G. Wilfong;Y. Yang;Chuanxiong Guo
中科院分区:
其他
文献类型:
--
作者:
Erran L. Li;Vahid Liaghat;Hongze Zhao;M. Hajiaghayi;Dan Li;G. Wilfong;Y. Yang;Chuanxiong Guo

文献摘要

被引文献

相似文献

虚拟化和弹性(私有或公共)云计算基础设施等新功能的出现使得在同一云基础设施上按需部署多个应用程序成为可能。然而,实现这种可能性的主要挑战在于,现代应用通常是分布式的结构化系统,其不仅包括计算和存储实体,还包括策略实体(例如,负载平衡器、防火墙、入侵防御盒)。在没有策略实体的云基础设施上部署应用程序可能会引入大量的策略违规和/或安全漏洞。在本文中,我们提出了PACE:第一个用于策略感知应用云嵌入的系统框架。我们精确地定义了策略感知的云应用程序嵌入问题,研究了其复杂性,并引入了简单,高效,在线的原始-对偶算法来嵌入云数据中心的应用程序。我们使用来自真实的大型园区网络和现实数据中心拓扑的数据进行评估,以评估PACE的可行性和性能。我们表明,在云中部署而不考虑网络内策略可能会导致大量的策略违规(例如,使用树路由作为实施网络内策略的方式可以观察到高达91%的策略违反)。我们还表明,我们的嵌入算法是非常有效的,通过比较一个很好的在线分数嵌入算法。
The emergence of new capabilities such as virtualization and elastic (private or public) cloud computing infrastructures has made it possible to deploy multiple applications, on demand, on the same cloud infrastructure. A major challenge to achieve this possibility, however, is that modern applications are typically distributed, structured systems that include not only computational and storage entities, but also policy entities (e.g., load balancers, firewalls, intrusion prevention boxes). Deploying applications on a cloud infrastructure without the policy entities may introduce substantial policy violations and/or security holes. In this paper, we present PACE: the first systematic framework for Policy-Aware Application Cloud Embedding. We precisely define the policy-aware, cloud application embedding problem, study its complexity and introduce simple, efficient, online primal-dual algorithms to embed applications in cloud data centers. We conduct evaluations using data from a real, large campus network and a realistic data center topology to evaluate the feasibility and performance of PACE. We show that deployment in a cloud without considering in-network policies may lead to a large number of policy violations (e.g., using tree routing as a way to enforce in-network policies may observe up to 91% policy violations). We also show that our embedding algorithms are very efficient by comparing with a good online fractional embedding algorithm.