DocumentCode
2959796
Title
EnforSDN: Network policies enforcement with SDN
Author
Ben-Itzhak, Yaniv ; Barabash, Katherine ; Cohen, Rami ; Levin, Anna ; Raichstein, Eran
Author_Institution
IBM Res. Lab., Haifa, Israel
fYear
2015
fDate
11-15 May 2015
Firstpage
80
Lastpage
88
Abstract
Network services, such as security, load-balancing, and monitoring, are an indisputable part of modern networking infrastructure and are traditionally realized as specialized appliances or middleboxes. Middleboxes complicate the management, the deployment, and the operations of the entire network. Moreover, they induce network performance issues and scalability limitations by requiring huge amounts of traffic to be, often sub-optimally redirected, and sometimes redundantly processed. Recent trends of server virtualization and Network Function Virtualization (NFV) exacerbate these scalability and performance issues. In this paper, we present EnforSDN - a new management approach that exploits SDN principles to decouple the policy resolution layer from the policy enforcement layer in network service appliances. Our approach improves the enforcement management, network utilization and communication latency, without compromising the policy and the functionality of the network. Using emulated SDN-based data center environment, we demonstrate higher throughput and lower latency achieved with EnforSDN, as compared to a baseline SDN network. In addition, we show that EnforSDN reduces the overall network appliances load, as well as the forwarding tables size.
Keywords
computer centres; computer network security; software defined networking; virtualisation; EnforSDN; NFV; communication latency; emulated SDN-based data center environment; enforcement management; load-balancing service; management approach; middleboxes; monitoring service; network function virtualization; network policies enforcement; network service appliances; network utilization; policy enforcement layer; policy resolution layer; security service; server virtualization; Firewalls (computing); Home appliances; Middleboxes; Network topology; Routing; Throughput; Middleboxes; Network Function Vir-tualization; Software-Defined Networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Integrated Network Management (IM), 2015 IFIP/IEEE International Symposium on
Conference_Location
Ottawa, ON
Type
conf
DOI
10.1109/INM.2015.7140279
Filename
7140279
Link To Document