Title :
EnforSDN: Network policies enforcement with SDN
Author :
Ben-Itzhak, Yaniv ; Barabash, Katherine ; Cohen, Rami ; Levin, Anna ; Raichstein, Eran
Author_Institution :
IBM Res. Lab., Haifa, Israel
Abstract :
Network services, such as security, load-balancing, and monitoring, are an indisputable part of modern networking infrastructure and are traditionally realized as specialized appliances or middleboxes. Middleboxes complicate the management, the deployment, and the operations of the entire network. Moreover, they induce network performance issues and scalability limitations by requiring huge amounts of traffic to be, often sub-optimally redirected, and sometimes redundantly processed. Recent trends of server virtualization and Network Function Virtualization (NFV) exacerbate these scalability and performance issues. In this paper, we present EnforSDN - a new management approach that exploits SDN principles to decouple the policy resolution layer from the policy enforcement layer in network service appliances. Our approach improves the enforcement management, network utilization and communication latency, without compromising the policy and the functionality of the network. Using emulated SDN-based data center environment, we demonstrate higher throughput and lower latency achieved with EnforSDN, as compared to a baseline SDN network. In addition, we show that EnforSDN reduces the overall network appliances load, as well as the forwarding tables size.
Keywords :
computer centres; computer network security; software defined networking; virtualisation; EnforSDN; NFV; communication latency; emulated SDN-based data center environment; enforcement management; load-balancing service; management approach; middleboxes; monitoring service; network function virtualization; network policies enforcement; network service appliances; network utilization; policy enforcement layer; policy resolution layer; security service; server virtualization; Firewalls (computing); Home appliances; Middleboxes; Network topology; Routing; Throughput; Middleboxes; Network Function Vir-tualization; Software-Defined Networks;
Conference_Titel :
Integrated Network Management (IM), 2015 IFIP/IEEE International Symposium on
Conference_Location :
Ottawa, ON
DOI :
10.1109/INM.2015.7140279