NeTS: Medium: Collaborative Research: Enabling Flexible Middlebox Processing in the Cloud
NeTS: Medium: Collaborative Research: Enabling Flexible Middlebox Processing in the Cloud
批准号:
1440056
负责人:
Vyas Sekar
金额:
$50.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-01-01 至 2019-08-31
中文摘要
企业依赖专门的网络设备或中间盒,如负载均衡器、入侵检测和防御系统以及广域网优化器,以满足关键的性能优化、安全和策略合规性要求。随着云计算的到来,由于两个关键因素,这种中间盒处理将在云部署中发挥越来越重要的作用:1)随着企业将其IT基础设施转移到云上,他们希望为在云中运行的应用程序利用相同的性能和安全优势;2)企业希望通过将中间盒功能卸载给云提供商来利用云计算提供的弹性扩展和迁移优势来降低基础设施和管理成本。遗憾的是,如今的云客户和提供商缺乏实现这一过渡所需的抽象概念和机制。从高层次来看,问题在于这些工作负载与云计算极为成功的传统计算和存储服务截然不同。这在几个维度上提出了基本挑战:需要灵活地组合或链接网络服务;网络级性能对此类工作负载的影响增加;在多路复用云部署中识别瓶颈资源的固有困难;以及无法在动态部署场景中对有状态网络处理的正确和一致操作进行推理。该项目将通过解决以下设计和实现中的基本问题来弥合这种脱节:(1)策略框架、弹性扩展算法和软件定义的控制器,供企业管理员将其要求转化为实际的物理实现;(2)用于智能网络级布局、流量工程的算法,以及云提供商支持此类工作负载的拓扑设计;以及(3)用于管理和操纵网络的中间盒关联状态的新抽象。更广泛的影响:随着企业和云提供商试图实现网络虚拟化的好处,这项工作将为关键的行业发展提供信息。此外,该项目将为今天不存在的网络部署提供新的灵活性维度--使中间盒的好处对小型企业大众化;提供灵活扩展网络级服务以满足应用需求的能力;以及使整个企业部署能够跨物理基础设施进行实时迁移。该项目将生成关于软件定义网络和云计算的新课程材料,并将研究与教育紧密结合,帮助学生成为这些新兴领域的专家。研究产生的软件工具和基准测量数据将为行业转型和未来有关云中中间盒部署的学术工作提供信息。最后,虽然该项目专注于云部署中的中间盒,但其中开发的技术基础也将适用于传统的企业和ISP网络。
英文摘要
Enterprises rely on specialized network appliances or middleboxes such as load balancers, intrusion detection and prevention systems, and WAN optimizers in order to meet critical performance optimization, security, and policy compliance requirements. With the advent of cloud computing, such middlebox processing will play an increasingly critical role in cloud deployments due to two key factors: 1) As enterprises move their IT infrastructure to the cloud, they want to leverage the same performance and security benefits for applications running in the cloud; and 2) Enterprises want to reduce their infrastructure and management costs by offloading middlebox functionality to cloud providers to leverage the elastic scaling and migration benefits offered by cloud computing. Unfortunately, cloud customers and providers today lack the necessary abstractions and mechanisms for enabling this transition. At a high-level, the problem is that these workloads are drastically different from traditional computation and storage services for which cloud computing has been extremely successful. This raises fundamental challenges along several dimensions: the need for flexible composition or chaining of network services; the increased impact of network-level performance on such workloads; the inherent difficulty in identifying bottlenecked resources in multiplexed cloud deployments; and the inability to reason about correct and consistent operation of stateful network processing in dynamic deployment scenarios.This project will bridge this disconnect by addressing foundational issues in the design and implementation of (1) policy frameworks, elastic scaling algorithms, and software-defined controllers for enterprise administrators to translate their requirements into an actual physical realization; (2) algorithms for intelligent network-level placement, traffic engineering, and topology design for cloud providers to support such workloads; and (3) new abstractions for managing and manipulating the middlebox-associated state of the network. Broader Impact: This work will inform the critical industry evolution as enterprises and cloud providers are attempting to realize the benefits of ?network virtualization?. Furthermore, the project will enable new dimensions of flexibility for network deployments that do not exist today---democratizing the benefits of middleboxes to small businesses; providing the ability to elastically scale network-level services to meet application demands; and enabling live migration of entire enterprise deployments across physical infrastructures. The project will generate new course materials on software-defined networking and cloud computing and tightly integrate research with education to help students become experts in these emerging domains. The software tools and benchmark measurement data produced by the research will inform the industry transition and future academic work on such middleboxes-in-the-cloud deployments. Finally, while the project focuses on middleboxes in cloud deployments, the technical foundations developed therein will apply to traditional enterprise and ISP networks as well.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: ONSET: Optics-enabled Network Defenses for Extreme Terabit DDoS Attacks
-
批准号:2132639
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2022
-
负责人:Vyas Sekar
-
依托单位:
Collaborative Research: CNS: Medium: Scalable Learning from Distributed Data for Wireless Network Management
-
批准号:2106214
-
项目类别:Continuing Grant
-
资助金额:$20.0万
-
财政年份:2021
-
负责人:Vyas Sekar
-
依托单位:
NSF NeTS Early-Career Investigators Workshop 2017
-
批准号:1743525
-
项目类别:Standard Grant
-
资助金额:$4.2万
-
财政年份:2017
-
负责人:Vyas Sekar
-
依托单位:
CAREER: Checking Dynamic Policies in Stateful Next-Generation Networks
-
批准号:1552481
-
项目类别:Continuing Grant
-
资助金额:$61.26万
-
财政年份:2016
-
负责人:Vyas Sekar
-
依托单位:
TWC: Medium: Handling a Trillion Unfixable Flaws on Billions of Internet-of-Things
-
批准号:1564009
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2016
-
负责人:Vyas Sekar
-
依托单位:
I-Corps: Exploring Commercialization Opportunities for a Software-Defined Approach for Securing Internet of Things
-
批准号:1644587
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2016
-
负责人:Vyas Sekar
-
依托单位:
NeTS: Medium: Collaborative Research: Flexible All-Wireless Inter-Rack Fabric for Datacenters Using Free-Space Optics
-
批准号:1513764
-
项目类别:Standard Grant
-
资助金额:$24.0万
-
财政年份:2015
-
负责人:Vyas Sekar
-
依托单位:
Proposal to Support Student Travel for the ACM SIGCOMM 2015 Conference
-
批准号:1538878
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2015
-
负责人:Vyas Sekar
-
依托单位:
AitF: FULL: Collaborative Research: Practical Foundations for Software-Defined Network Optimization
-
批准号:1536002
-
项目类别:Standard Grant
-
资助金额:$34.67万
-
财政年份:2015
-
负责人:Vyas Sekar
-
依托单位:
TWC: Frontier: Collaborative: Rethinking Security in the Era of Cloud Computing
-
批准号:1440065
-
项目类别:Continuing Grant
-
资助金额:$74.98万
-
财政年份:2014
-
负责人:Vyas Sekar
-
依托单位:
NeTS: Medium: Collaborative Research: Enabling Flexible Middlebox Processing in the Cloud
-
批准号:1302412
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2013
-
负责人:Vyas Sekar
-
依托单位:
TWC: Frontier: Collaborative: Rethinking Security in the Era of Cloud Computing
-
批准号:1329641
-
项目类别:Continuing Grant
-
资助金额:$74.98万
-
财政年份:2013
-
负责人:Vyas Sekar
-
依托单位:
海外基金