Rosemary: A Robust, Secure, and High-Performance Network Operating System

被引:142
|
作者
Shin, Seungwon [1 ]
Song, Yongjoo [2 ]
Lee, Taekyung [2 ]
Lee, Sangho [2 ]
Chung, Jaewoong [2 ]
Porras, Phillip [3 ]
Yegneswaran, Vinod [3 ]
Noh, Jiseong [1 ]
Kang, Brent Byunghoon [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Daejeon, South Korea
[2] Atto Res, Amherst, NY USA
[3] SRI Int, Menlo Pk, CA 94025 USA
关键词
Software-Defined Network (SDN); OpenFlow; Controller Robustness;
D O I
10.1145/2660267.2660353
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Within the hierarchy of the Software Defined Network (SDN) network stack, the control layer operates as the critical middleware facilitator of interactions between the data plane and the network applications, which govern flow routing decisions. In the OpenFlow implementation of the SDN model, the control layer, commonly referred to as a network operating system (NOS), has been realized by a range of competing implementations that offer various performance and functionality advantages: Floodlight [11], PDX [30], NOX [14], and ONIX [18]. In this paper we focus on the question of control layer resilience, when rapidly developed prototype network applications go awry, or third-party network applications incorporate unexpected vulnerabilities, fatal instabilities, or even malicious logic. We demonstrate how simple and common failures in a network application may lead to loss of the control layer, and in effect, loss of network control. To address these concerns we present the ROSEMARY controller, which implements a network application containment and resilience strategy based around the notion of spawning applications independently within a micro-NOS. ROSEMARY distinguishes itself by its blend of process containment, resource utilization monitoring, and an application permission structure, all designed to prevent common failures of network applications from halting operation of the SDN Stack. We present our design and implementation of ROSEMARY, along with an extensive evaluation of its performance relative to several of the mostly well-known and widely used controllers. Rather than imposing significant performance costs, we find that with the integration of two optimization features, ROSEMARY offers a competitive performance advantage over the majority of other controllers.
引用
收藏
页码:78 / 89
页数:12
相关论文
共 50 条
  • [21] Blockmon: A High-Performance Composable Network Traffic Measurement System
    Huici, Felipe
    di Pietro, Andrea
    Trammell, Brian
    Hidalgo, Jose Maria
    Ruiz, Daniel Martinez
    d'Heureuse, Nico
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2012, 42 (04) : 79 - 80
  • [22] Design and implementation of a high-performance network intrusion prevention system
    Xinidis, K
    Anagnostakis, KG
    Markatos, EP
    Security and Privacy in the Age of Ubiquitous Computing, 2005, 181 : 359 - 374
  • [23] Building a high-performance communication framework for network isolation system
    Wu, Haiyan
    Tan, Chengxiang
    Wang, Haihang
    PROCEEDINGS OF 2008 IEEE INTERNATIONAL CONFERENCE ON NETWORKING, SENSING AND CONTROL, VOLS 1 AND 2, 2008, : 1086 - 1091
  • [24] The Effects of High-Performance Cloud System for Network Function Virtualization
    Chung, Wu-Chun
    Wang, Yun-He
    APPLIED SCIENCES-BASEL, 2022, 12 (20):
  • [25] OPERATING PARAMETERS IN HIGH-PERFORMANCE DISPLACEMENT CHROMATOGRAPHY
    HORVATH, C
    FRENZ, J
    ELRASSI, Z
    JOURNAL OF CHROMATOGRAPHY, 1983, 255 (JAN): : 273 - 293
  • [26] A methodology for high-performance operating interface design
    Lo, Chi-Hung
    Ko, Ya-Chuan
    Hsiao, Shih-Wen
    CONCURRENT ENGINEERING-RESEARCH AND APPLICATIONS, 2015, 23 (02): : 110 - 123
  • [27] Building High-Performance Teams in the Operating Room
    Sax, Harry C.
    SURGICAL CLINICS OF NORTH AMERICA, 2012, 92 (01) : 15 - +
  • [28] MACROLAN - A HIGH-PERFORMANCE NETWORK
    STEVENS, RW
    PROCEEDINGS OF THE SOCIETY OF PHOTO-OPTICAL INSTRUMENTATION ENGINEERS, 1984, 468 : 88 - 93
  • [29] LOS: A High Performance and Compatible User-level Network Operating System
    Huang, Yukai
    Geng, Jinkun
    Lin, Du
    Wang, Bin
    Li, Junfeng
    Ling, Ruilin
    Li, Dan
    PROCEEDINGS OF THE 2017 ASIA-PACIFIC WORKSHOP ON NETWORKING (APNET '17), 2017, : 50 - 56
  • [30] High-performance flexible lithium-ion electrodes based on robust network architecture
    Jia, Xilai
    Chen, Zheng
    Suwarnasarn, Arnold
    Rice, Lynn
    Wang, Xiaolei
    Sohn, Hiesang
    Zhang, Qiang
    Wu, Benjamin M.
    Wei, Fei
    Lu, Yunfeng
    ENERGY & ENVIRONMENTAL SCIENCE, 2012, 5 (05) : 6845 - 6849