In this paper, we analyse the deployment of middlebox. For a given network information and policy requirements, an attempt is made to determine the optimal location of middlebox to achieve the best performance. In ter...In this paper, we analyse the deployment of middlebox. For a given network information and policy requirements, an attempt is made to determine the optimal location of middlebox to achieve the best performance. In terms of the end-to-end delay as a performance optimization index, a distributed middlebox placement algorithm based on potential game is proposed. Through extensive simulations, it demonstrates that the proposed algorithm achieves the near-optimal solution, and the end-to-end delay decreases significantly.展开更多
随着移动计算技术的高速发展,HIP因其在移动主机支持及安全等方面的优越特性而备受关注.可尽管HIP在保护通信两端方面具有卓越的安全特性,但作为HIP通信节点的中间系统(如NAT/FW系统)却不能得到有效保护,尤其是在不对称路由环境下的HIP...随着移动计算技术的高速发展,HIP因其在移动主机支持及安全等方面的优越特性而备受关注.可尽管HIP在保护通信两端方面具有卓越的安全特性,但作为HIP通信节点的中间系统(如NAT/FW系统)却不能得到有效保护,尤其是在不对称路由环境下的HIP中间系统,很容易遭受攻击.本文在分析HIP通信及其中间系统的基础上,结合HIP注册扩展协议,提出一种在不对称路由情况下的安全的基于HTN(HIP through NATs)的HIP中间系统模型.该系统不仅让HIP通信主机可以感知链路上的NAT等中间系统,HIP中间系统也可以通过注册协议,来学习连接状态信息,并验证通信发起主机是否真正感兴趣于成功建立HIP连接,并为后续更新报文的验证提供可信依据,从而有效避免遭受DoS及MitM攻击.展开更多
To address the issues that middleboxes as a fundamental part of today's networks are facing, Network Function Virtualization(NFV)has been recently proposed, which in essence asserts to migrate hardware-based middl...To address the issues that middleboxes as a fundamental part of today's networks are facing, Network Function Virtualization(NFV)has been recently proposed, which in essence asserts to migrate hardware-based middleboxes into software-based virtualized function entities.Due to the demands of virtual services placement in NFV network environment, this paper models the service amount placement problem involving with the resources allocation as a cooperative game and proposes the placement policy by Nash Bargaining Solution(NBS). Specifically,we first introduce the system overview and apply the rigorous cooperative game-theoretic guide to build the mathematical model, which can give consideration to both the responding efficiency of service requirements and the allocation fairness.Then a distributed algorithm corresponding to NBS is designed to achieve predictable network performance for virtual instances placement.Finally, with simulations under various scenarios,the results show that our placement approach can achieve high utilization of network through the analysis of evaluation metrics namely the satisfaction degree and fairness index. With the suitable demand amount of services, the average values of two metrics can reach above 90%. And by tuning the base placement, our solution can enable operators to flexibly balance the tradeoff between satisfaction and fairness of resourcessharing in service platforms.展开更多
网络功能虚拟化(network function virtualization,NFV)基于虚拟化技术和标准的商业服务器、交换机、存储器来实现网络功能,用于替代网络中原本采用专用设备的中间盒,为运营商减少了搭建和运营网络的开销,提高了网络服务的灵活性、可扩...网络功能虚拟化(network function virtualization,NFV)基于虚拟化技术和标准的商业服务器、交换机、存储器来实现网络功能,用于替代网络中原本采用专用设备的中间盒,为运营商减少了搭建和运营网络的开销,提高了网络服务的灵活性、可扩展性,促进了新兴网络功能的开发和部署.目前NFV仍然处于发展阶段,在系统性能、管理编排、可靠性、可用性、安全性、可编程性等方面仍然存在很多问题,研究人员围绕这些问题展开了大量的研究.对NFV体系结构和基础技术进行了总结,提出了需要解决的关键问题.在此基础上,对已有的NFV研究成果提出了"四象限"的分类方法,并详细分析和比较了典型的解决方案,总结了各方案的优势和开销,对未来的研究趋势进行了展望.展开更多
尽管软件定义网络(Software Defined Networking,SDN)的安全性得到了极大的关注,但SDN控制器受大流UDP冗余分组威胁的问题并没有得到有效解决。对此,基于SDN和网络功能虚拟化(Network Function Virtualization,NFV)技术的特点,结合SDN...尽管软件定义网络(Software Defined Networking,SDN)的安全性得到了极大的关注,但SDN控制器受大流UDP冗余分组威胁的问题并没有得到有效解决。对此,基于SDN和网络功能虚拟化(Network Function Virtualization,NFV)技术的特点,结合SDN控制器处理UDP和TCP两种数据流时的负载状况,首先提出了一种新型的基于NFV的防范SDN控制器中UDP冗余分组的机制,前置于OpenFlow交换机口的检测中间盒能够有效地检测并滤除UDP流冗余分组;其次,提出了一种经济有效的基于NFV的检测中间盒的实现方法,使用Linux容器实现检测中间盒,在SDN控制器下发流表之前只允许UDP流首分组通过中间盒,保证后续UDP流分组在到达OpenFlow交换机时已经有相关的流表项存在;最后,在Linux服务器中实现了基于该机制的原型系统并进行实验。结果表明,当非首分组的时延 t 大于或等于控制器处理单个分组的时间时,该方法能够有效地解除UDP冗余分组的威胁。展开更多
在软件定义网络中,通过网络功能虚拟化(network function virtualization,NFV)可以有效地优化中间盒的部署以及数据包的路由,但是受中间盒之间存在的依赖关系约束,不适当的部署策略会为运营商带来额外的路由成本,降低资源利用率。为此,...在软件定义网络中,通过网络功能虚拟化(network function virtualization,NFV)可以有效地优化中间盒的部署以及数据包的路由,但是受中间盒之间存在的依赖关系约束,不适当的部署策略会为运营商带来额外的路由成本,降低资源利用率。为此,文章建立混合整数线性规划模型,提出一种服务链感知精准算法用于计算受中间盒依赖关系以及链路带宽约束的最小路由成本。该算法首先基于中间盒的依赖关系构造有向层级图,然后从该层级图中的源点到终点之间的最短路径中筛选出满足带宽要求的链路作为数据包的路由。仿真实验结果表明,该算法可以快速获取最优解,具有较好的应用前景。展开更多
Despite the critical role that middleboxes play in introducing new network functionality,management and innovation of them are still severe challenges for network operators,since traditional middleboxes based on hardw...Despite the critical role that middleboxes play in introducing new network functionality,management and innovation of them are still severe challenges for network operators,since traditional middleboxes based on hardware lack service flexibility and scalability.Recently,though new networking technologies,such as network function virtualization(NFV) and softwaredefined networking(SDN),are considered as very promising drivers to design cost-efficient middlebox service architectures,how to guarantee transmission efficiency has drawn little attention under the condition of adding virtual service process for traffic.Therefore,we focus on the service deployment problem to reduce the transport delay in the network with a combination of NFV and SDN.First,a framework is designed for service placement decision,and an integer linear programming model is proposed to resolve the service placement and minimize the network transport delay.Then a heuristic solution is designed based on the improved quantum genetic algorithm.Experimental results show that our proposed method can calculate automatically the optimal placement schemes.Our scheme can achieve lower overall transport delay for a network compared with other schemes and reduce 30% of the average traffic transport delay compared with the random placement scheme.展开更多
文摘In this paper, we analyse the deployment of middlebox. For a given network information and policy requirements, an attempt is made to determine the optimal location of middlebox to achieve the best performance. In terms of the end-to-end delay as a performance optimization index, a distributed middlebox placement algorithm based on potential game is proposed. Through extensive simulations, it demonstrates that the proposed algorithm achieves the near-optimal solution, and the end-to-end delay decreases significantly.
文摘随着移动计算技术的高速发展,HIP因其在移动主机支持及安全等方面的优越特性而备受关注.可尽管HIP在保护通信两端方面具有卓越的安全特性,但作为HIP通信节点的中间系统(如NAT/FW系统)却不能得到有效保护,尤其是在不对称路由环境下的HIP中间系统,很容易遭受攻击.本文在分析HIP通信及其中间系统的基础上,结合HIP注册扩展协议,提出一种在不对称路由情况下的安全的基于HTN(HIP through NATs)的HIP中间系统模型.该系统不仅让HIP通信主机可以感知链路上的NAT等中间系统,HIP中间系统也可以通过注册协议,来学习连接状态信息,并验证通信发起主机是否真正感兴趣于成功建立HIP连接,并为后续更新报文的验证提供可信依据,从而有效避免遭受DoS及MitM攻击.
基金supported by The National Basic Research Program of China (973) (Grant No. 2012CB315901, 2013CB329104)The National Natural Science Foundation of China (Grant No. 61521003, 61372121, 61309019, 61572519, 61502530)The National High Technology Research and Development Program of China (863) (Grant No. 2015AA016102)
文摘To address the issues that middleboxes as a fundamental part of today's networks are facing, Network Function Virtualization(NFV)has been recently proposed, which in essence asserts to migrate hardware-based middleboxes into software-based virtualized function entities.Due to the demands of virtual services placement in NFV network environment, this paper models the service amount placement problem involving with the resources allocation as a cooperative game and proposes the placement policy by Nash Bargaining Solution(NBS). Specifically,we first introduce the system overview and apply the rigorous cooperative game-theoretic guide to build the mathematical model, which can give consideration to both the responding efficiency of service requirements and the allocation fairness.Then a distributed algorithm corresponding to NBS is designed to achieve predictable network performance for virtual instances placement.Finally, with simulations under various scenarios,the results show that our placement approach can achieve high utilization of network through the analysis of evaluation metrics namely the satisfaction degree and fairness index. With the suitable demand amount of services, the average values of two metrics can reach above 90%. And by tuning the base placement, our solution can enable operators to flexibly balance the tradeoff between satisfaction and fairness of resourcessharing in service platforms.
文摘网络功能虚拟化(network function virtualization,NFV)基于虚拟化技术和标准的商业服务器、交换机、存储器来实现网络功能,用于替代网络中原本采用专用设备的中间盒,为运营商减少了搭建和运营网络的开销,提高了网络服务的灵活性、可扩展性,促进了新兴网络功能的开发和部署.目前NFV仍然处于发展阶段,在系统性能、管理编排、可靠性、可用性、安全性、可编程性等方面仍然存在很多问题,研究人员围绕这些问题展开了大量的研究.对NFV体系结构和基础技术进行了总结,提出了需要解决的关键问题.在此基础上,对已有的NFV研究成果提出了"四象限"的分类方法,并详细分析和比较了典型的解决方案,总结了各方案的优势和开销,对未来的研究趋势进行了展望.
文摘尽管软件定义网络(Software Defined Networking,SDN)的安全性得到了极大的关注,但SDN控制器受大流UDP冗余分组威胁的问题并没有得到有效解决。对此,基于SDN和网络功能虚拟化(Network Function Virtualization,NFV)技术的特点,结合SDN控制器处理UDP和TCP两种数据流时的负载状况,首先提出了一种新型的基于NFV的防范SDN控制器中UDP冗余分组的机制,前置于OpenFlow交换机口的检测中间盒能够有效地检测并滤除UDP流冗余分组;其次,提出了一种经济有效的基于NFV的检测中间盒的实现方法,使用Linux容器实现检测中间盒,在SDN控制器下发流表之前只允许UDP流首分组通过中间盒,保证后续UDP流分组在到达OpenFlow交换机时已经有相关的流表项存在;最后,在Linux服务器中实现了基于该机制的原型系统并进行实验。结果表明,当非首分组的时延 t 大于或等于控制器处理单个分组的时间时,该方法能够有效地解除UDP冗余分组的威胁。
文摘在软件定义网络中,通过网络功能虚拟化(network function virtualization,NFV)可以有效地优化中间盒的部署以及数据包的路由,但是受中间盒之间存在的依赖关系约束,不适当的部署策略会为运营商带来额外的路由成本,降低资源利用率。为此,文章建立混合整数线性规划模型,提出一种服务链感知精准算法用于计算受中间盒依赖关系以及链路带宽约束的最小路由成本。该算法首先基于中间盒的依赖关系构造有向层级图,然后从该层级图中的源点到终点之间的最短路径中筛选出满足带宽要求的链路作为数据包的路由。仿真实验结果表明,该算法可以快速获取最优解,具有较好的应用前景。
基金supported by the National Basic Research Program(973)of China(Nos.2012CB315901 and 2013CB329104)the National Natural Science Foundation of China(Nos.61309019,61372121,61572519,and 61502530)the National High-Tech R&D Program(863)of China(Nos.2015AA016102 and 2013AA013505)
文摘Despite the critical role that middleboxes play in introducing new network functionality,management and innovation of them are still severe challenges for network operators,since traditional middleboxes based on hardware lack service flexibility and scalability.Recently,though new networking technologies,such as network function virtualization(NFV) and softwaredefined networking(SDN),are considered as very promising drivers to design cost-efficient middlebox service architectures,how to guarantee transmission efficiency has drawn little attention under the condition of adding virtual service process for traffic.Therefore,we focus on the service deployment problem to reduce the transport delay in the network with a combination of NFV and SDN.First,a framework is designed for service placement decision,and an integer linear programming model is proposed to resolve the service placement and minimize the network transport delay.Then a heuristic solution is designed based on the improved quantum genetic algorithm.Experimental results show that our proposed method can calculate automatically the optimal placement schemes.Our scheme can achieve lower overall transport delay for a network compared with other schemes and reduce 30% of the average traffic transport delay compared with the random placement scheme.