期刊文献+

容器化安全服务功能链低延迟优化编排研究 被引量:4

Low-latency Optimal Orchestration of Containerized Security Service Function Chain
下载PDF
导出
摘要 云计算的发展带来了安全服务虚拟化的需求,基于NFV/SDN技术构建服务功能链是解决数据中心虚拟化安全服务需求的重要途径。容器化已成为安全服务功能链编排的最新发展趋势。传统安全服务功能链编排算法通常针对虚拟机架构,在轻量级、延迟、灵活性等方面无法满足要求,没有充分发挥容器化NFV平台的性能优势。文章构建了容器化NFV平台的编排模型,分析了安全服务功能链网络延迟优化目标,研究了扁平网络拓扑下的近似局部最优性质。文章设计了一种延迟优化放置(LOP)算法,采用分阶段决策方式处理每个安全服务功能链请求,并在每个阶段采用选择可容纳连续VNF数最多的物理主机的方式,最小化每个安全服务功能链的跨主机延迟。仿真实验与对比分析表明,与最大化资源利用率的MINI算法相比,文章所提出的LOP算法可以实现降低延迟的优化目标,减少放置安全服务功能链的资源消耗。 The development of cloud computing brings the need for security services virtualization. Building SFC(service function chain) based on NFV/SDN technology is an important way to meet the need of virtualized security services in data centers. Containerization has become the latest development trend of security SFC orchestration. Traditional security SFC orchestration algorithms are usually on the virtual machine architectures, which can not meet requirements in lightweight, latency, flexibility, etc., and have not fully utilized the performance advantages of containerized NFV platform. This paper constructs a containerized NFV platform orchestration model, analyzes the network latency optimization goal of security SFC, and studies the approximate local optimization property under flat network topology. This paper proposes a latency optimal placement(LOP) algorithm, which uses multi-stage decision to handle each security SFC request, and in each stage, a physical host that can hold the maximum number of consecutive VNFs is selected to minimize the cross host latency of each security SFC. Simulation experiments and comparative analysis show that, compared with MINI algorithm that maximizes resource utilization, the LOP algorithm proposed in this paper can achieve the optimization goal of reducing latency, and can reduce the resource consumption of placing the security SFC.
作者 徐玉伟 赵宝康 时向泉 苏金树 XU Yuwei;ZHAO Baokang;SHI Xiangquan;SU Jinshu(College of Computer,National University of Defense Technology,Changsha 410073,China)
出处 《信息网络安全》 CSCD 北大核心 2020年第7期11-18,共8页 Netinfo Security
基金 国家自然科学基金[61972412]。
关键词 云安全 容器网络 服务功能链 延迟优化 cloud security container network service function chain latency optimization
  • 相关文献

参考文献3

二级参考文献16

  • 1Cisco Visual. Networking Index Global mobile data traffic forecast update, 2012-2017[OL].http://www.cisco.com/en/ US/solutions/collateral/ns341/ns525/ns537/ns705/ns827/ white paper c11-520862, 2013.
  • 2Marketing Charts Staff. Mobile network operators face cost crunch[OL].http://www.marketingcharts.com/wp/direct/ mobile-network operators-face-cost-crunch-17700/, 2011.
  • 3HAWILO H, SHAMI A, MIRAHMADI M, et al. NVF: State of the art, challenges, and implementation in next generation mobile networks (vEPC)[J].IEEE Networks, 2014, 28(6): 18-26. doi: 10.1109/MNET.2014.6963800.
  • 4LI L E, LIAGHAT V, ZHAO H, et al. PACE: Policy-aware application cloud embedding[C].IEEE International Conference on Computer Communication, Turin, 2013: 638-646. doi: 10.1109/INFCOM.2013.6566849.
  • 5ZHANG Y, BEHESHTI N, BELIVEAU L, et al. Steering: A software-defined networking for inline service chaining[C].IEEE International Conference on Network Protocols (ICNP), Rio de Janeiro, 2013: 1-10. doi: 10.1109/ICNP. 2013.6733615.
  • 6GIANNOULAKIS I, KAFETZAKIS E, XYLOURIS G, et al. On the applications of efficient NFV management towards 5G networking[C].IEEE International Conference on 5G for Ubiquitous Connectivity, Levi, 2014: 1-5. doi: 10.4108/ icst.5gu.2014.2581 33.
  • 7MOENS H and DE TURCK F. VNF-P: a model for efficient placement of virtualized network functions[C].IEEE International Conference on Network and Service Management, Rio de Janeiro, 2014: 418-423. doi: 10.1109/ CNSM.2014.7014205.
  • 8CLAYMAN S, MAINI E, GALIS A, et al. The dynamic placement of virtual network functions[C].IEEE International Conference on Network Operations and Management Symposium, Krakow, 2014: 1-9. doi: 10.1109/ NOMS.2014.6838412.
  • 9XIA M, SHIRAZIPOUR M, ZHANG Y, et al. Network function placement for NFV chaining in packet/optical datacenters[J].Journal of Lightwave Technology, 2015, 33(8): 1565-1570. doi: 10.1109/JLT.2015.2388585.
  • 10YOUSAF F Z, LOUREIRO P, ZDARSKY F, et al. Cost analysis of initial deployment strategies for virtualized mobile core network functions[J].IEEE Communications Magazine, 2015, 53(12): 60-66. doi: 10.1109/MCOM.2015.7355586.

共引文献43

同被引文献35

引证文献4

二级引证文献12

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部