课题基金 / 基金详情

CNS Core: Small: Network-wide Policy Enforcement in Programmable Networks using Logical Queues

CNS Core: Small: Network-wide Policy Enforcement in Programmable Networks using Logical Queues
CNS 核心:小型:使用逻辑队列在可编程网络中执行全网络策略
批准号:
2008273
负责人:
Balajee Vamanan
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2024-09-30

项目摘要

项目成果

Balajee Vamanan的其他基金

相似基金

相关文献

中文摘要
翻译
数据中心网络和互联网交换点(ixp)是当今计算基础设施的重要组成部分,它们支持b谷歌、Facebook和Netflix等重要的云服务。在这些网络中,相互竞争的公司(租户)运行许多不同的分布式应用程序,这些应用程序通过网络进行通信。不幸的是,现有的网络不能确保这些相互竞争的应用程序是隔离的。例如,如果恶意承租者打开了比其他承租者更多的连接并向网络注入了更多的数据,那么它可能会消耗超出其公平份额的网络容量,并对其他承租者应用程序的性能产生不利影响。这项工作引入了一个新系统,它可以执行网络范围内的隔离策略,并确保竞争租户不能通过打开更多连接或注入更多数据来欺骗系统并获得更高的性能。提供网络内性能隔离的现有方法使用虚拟队列来隔离流量。不幸的是,这些方法在可伸缩性、性能、更新延迟和tcp友好性方面存在关键限制。为了克服这些限制,本提案旨在重新思考交换机如何跟踪和响应动态变化的流量模式以及如何通知终端主机拥塞信息的设计。具体来说,它将引入逻辑队列,它使用计数器近似地充当具有大量虚拟队列的交换机,而不需要相关的硬件成本。关键的见解是,由于今天的交换机已经将交换机资源(SRAM)专用于用于监视的计数器,因此可以重新利用这些相同的计数器来实现开销较低的逻辑队列。这项工作将对应用程序开发人员、网络硬件供应商、云提供商和云基础设施用户产生重大影响。新的抽象有可能在网络应用程序的开发和教学中变得普遍,并且有可能显著提高当今网络的性能和安全隔离。这一提议也有可能扩大当今可编程交换机的吸引力,并开辟一个新的细分市场。作为这项工作的一部分创建的软件将在灵活的开源许可下通过github (https://github.com/uic-data-center-systems/)广泛提供给公众重用。研究人员在向更广泛的研究社区发布其研究原型的源代码方面有着良好的记录。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Data center networks and Internet eXchange Points (IXPs) are a critical part of today's computing infrastructure that support important cloud services like Google, Facebook, and Netflix. In these networks, competing companies (tenants) run many different distributed applications that communicate across the network. Unfortunately, existing networks are not able to ensure that these competing applications are isolated. For example, if a malicious tenant were to open more connections and inject more data into the network than other tenants, it could consume more than its fair share of network capacity and adversely affect the performance of other tenants' applications. This work introduces a new system that can enforce network-wide isolation policies and ensure that competing tenants cannot game the system and get more performance by opening more connections or by injecting more data.Existing approaches to providing in-network performance isolation use virtual queues to isolate traffic. Unfortunately, these approaches suffer from key limitations with respect to scalability, performance, update latency, and TCP-friendliness. To overcome these limitations, this proposal aims to rethink the design of how switches track and respond to dynamically changing traffic patterns and how end-hosts are notified of congestion information. Specifically, it will introduce logical queues, which use counters to approximately behave as a switch with a large number of virtual queues without the associated hardware costs. The key insight is that since today's switches are already dedicating switch resources (SRAM) to counters that are used for monitoring, these same counters can be repurposed to implement logical queues with low overheads.This work will have significant implications for application developers, network hardware vendors, cloud providers, and users of cloud infrastructure. The new abstractions have the potential to become commonplace in both the development and teaching of network applications, and it has the potential to significantly improve performance and security isolation in today's networks. This proposal has the potential to also broaden the appeal of today’s programmable switches and open up a new segment of the market. The software created as part of this work will be made broadly available for public reuse under flexible open-source licenses through github (https://github.com/uic-data-center-systems/). The investigators have a strong record of releasing the source codes of their research prototypes to the broader research community.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
TCP is Harmful to In-Network Computing: Designing a Message Transport Protocol (MTP)
TCP 对网络内计算有害:设计消息传输协议 (MTP)
DOI: 10.1145/3484266.3487382
发表时间: 2021
期刊: HotNets
影响因子: --
作者: [Stephens, Brent E., Grassi, Darius, Almasi, Hamidreza, Ji, Tao, Vamanan, Balajee, Akella, Aditya]
通讯作者: Akella, Aditya
DOI: 10.1145/3482898.3483361
发表时间: 2021-10
期刊: Proceedings of the ACM SIGCOMM Symposium on SDN Research (SOSR)
影响因子: --
作者: [Vineeth Sagar Thapeta;Komal Shinde;Mojtaba MalekpourShahraki;Darius Grassi;Balajee Vamanan;Brent E. Stephens]
通讯作者: Vineeth Sagar Thapeta;Komal Shinde;Mojtaba MalekpourShahraki;Darius Grassi;Balajee Vamanan;Brent E. Stephens
ADA: Arithmetic Operations with Adaptive TCAM Population in Programmable Switches
ADA:可编程交换机中自适应 TCAM 群体的算术运算
DOI: 10.1109/icdcs54860.2022.00044
发表时间: 2022
期刊: International Conference on Distributed Computing Systems (ICDCS
影响因子: --
作者: [Malekpourshahraki, Mojtaba, Stephens, Brent E., Vamanan, Balajee]
通讯作者: Vamanan, Balajee
BIGDATA: Collaborative Research: F: RDMA-Based Datacenter Networks for Online Big Data Applications
  • 批准号:
    1633318
  • 项目类别:
    Standard Grant
  • 资助金额:
    $27.9万
  • 财政年份:
    2016
  • 负责人:
    Balajee Vamanan
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: