• DocumentCode
    947877
  • Title

    Measurement-Based Characterization of IP VPNs

  • Author

    Raghunath, Satish ; Ramakrishnan, K.K. ; Kalyanaraman, Shivkumar

  • Author_Institution
    Juniper Networks Inc., Sunnyvale
  • Volume
    15
  • Issue
    6
  • fYear
    2007
  • Firstpage
    1428
  • Lastpage
    1441
  • Abstract
    Virtual private networks (VPNs) provide secure and reliable communication between customer sites. With the increase in number and size of VPNs, providers need efficient provisioning techniques that adapt to customer demand by leveraging a good understanding of VPN properties. In this paper, we analyze two important properties of VPNs that impact provisioning: (1) structure of customer endpoint (CE) interactions and (2) temporal characteristics of CE-CE traffic. We deduce these properties by computing traffic matrices from SNMP measurements. We find that existing traffic matrix estimation techniques are not readily applicable to the VPN scenario due to the scale of the problem and limited measurement information. We begin by formulating a scalable technique that makes the most out of existing measurement information and provides good estimates for common VPN structures. We then use this technique to analyze SNMP measurement information from a large IP VPN service provider. We find that even with limited measurement information (no per-VPN data for the core) we can estimate traffic matrices for a significant fraction of VPNs, namely, those constituting the ldquoHub-and-Spokerdquo category. In addition, the ability to infer the structure of VPNs holds special significance for provisioning tasks arising from topology changes, link failures and maintenance. We are able to provide a classification of VPNs by structure and identify CEs that act as hubs of communication and hence require prioritized treatment during restoration and provisioning.
  • Keywords
    IP networks; customer satisfaction; telecommunication network reliability; telecommunication network topology; telecommunication security; telecommunication traffic; virtual private networks; CE-CE traffic temporal characteristics; IP VPN service provider; SNMP measurement information; communication reliability; customer demand; hub-and-spoke category; measurement-based characterization; secure communication; virtual private network; Provisioning; traffic engineering; traffic matrix estimation; virtual private network (VPN);
  • fLanguage
    English
  • Journal_Title
    Networking, IEEE/ACM Transactions on
  • Publisher
    ieee
  • ISSN
    1063-6692
  • Type

    jour

  • DOI
    10.1109/TNET.2007.896539
  • Filename
    4359155