Rosemary: A Robust, Secure, and High-Performance Network Operating System

被引:142
|
作者
Shin, Seungwon [1 ]
Song, Yongjoo [2 ]
Lee, Taekyung [2 ]
Lee, Sangho [2 ]
Chung, Jaewoong [2 ]
Porras, Phillip [3 ]
Yegneswaran, Vinod [3 ]
Noh, Jiseong [1 ]
Kang, Brent Byunghoon [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Daejeon, South Korea
[2] Atto Res, Amherst, NY USA
[3] SRI Int, Menlo Pk, CA 94025 USA
关键词
Software-Defined Network (SDN); OpenFlow; Controller Robustness;
D O I
10.1145/2660267.2660353
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Within the hierarchy of the Software Defined Network (SDN) network stack, the control layer operates as the critical middleware facilitator of interactions between the data plane and the network applications, which govern flow routing decisions. In the OpenFlow implementation of the SDN model, the control layer, commonly referred to as a network operating system (NOS), has been realized by a range of competing implementations that offer various performance and functionality advantages: Floodlight [11], PDX [30], NOX [14], and ONIX [18]. In this paper we focus on the question of control layer resilience, when rapidly developed prototype network applications go awry, or third-party network applications incorporate unexpected vulnerabilities, fatal instabilities, or even malicious logic. We demonstrate how simple and common failures in a network application may lead to loss of the control layer, and in effect, loss of network control. To address these concerns we present the ROSEMARY controller, which implements a network application containment and resilience strategy based around the notion of spawning applications independently within a micro-NOS. ROSEMARY distinguishes itself by its blend of process containment, resource utilization monitoring, and an application permission structure, all designed to prevent common failures of network applications from halting operation of the SDN Stack. We present our design and implementation of ROSEMARY, along with an extensive evaluation of its performance relative to several of the mostly well-known and widely used controllers. Rather than imposing significant performance costs, we find that with the integration of two optimization features, ROSEMARY offers a competitive performance advantage over the majority of other controllers.
引用
收藏
页码:78 / 89
页数:12
相关论文
共 50 条
  • [41] A high-performance clustering scheme with application in network intrusion prevention system
    Chiu, Chien-Hua
    Lin, Jung-Feng
    Lee, Jiunn-Jye
    Lei, Chin-Laung
    2007 INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES, VOLS 1-3, 2007, : 1219 - 1224
  • [42] HIGH-PERFORMANCE EXPERT SYSTEM - DBMS INTERFACE FOR NETWORK MANAGEMENT AND CONTROL
    WHANG, KY
    BRADY, S
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 1989, 7 (03) : 408 - 417
  • [43] Zodiac: System Architecture Implementation for a High-Performance Network Security Processor
    Wang Haixin
    Bai Guoqiang
    Chen Hongyi
    2008 INTERNATIONAL CONFERENCE ON APPLICATION-SPECIFIC SYSTEMS, ARCHITECTURES AND PROCESSORS, 2008, : 91 - 96
  • [44] A High-performance Tiered Storage System for a Global Spectrum Observatory Network
    Attard, Ryan
    Kalliovaara, Juha
    Taher, Tanim
    Taylor, Jesse
    Paavola, Jarkko
    Ekman, Reijo
    Roberson, Dennis
    2014 9TH INTERNATIONAL CONFERENCE ON COGNITIVE RADIO ORIENTED WIRELESS NETWORKS AND COMMUNICATIONS (CROWNCOM), 2014, : 466 - 473
  • [45] Design of secure operating system
    Mao, Weifeng
    Ping, Lingdi
    Jiang, Li
    Chen, Xiaoping
    Jisuanji Gongcheng/Computer Engineering, 2006, 32 (12): : 179 - 181
  • [46] Dedicated secure operating system
    Shi, Jun
    Zhu, Lu-Hua
    Shen, Chang-Xiang
    You, Jin-Yuan
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2002, 39 (05):
  • [47] INVESTIGATION OF OPERATING PARAMETERS IN HIGH-PERFORMANCE DISPLACEMENT CHROMATOGRAPHY
    FRENZ, J
    VANDERSCHRIECK, P
    HORVATH, C
    JOURNAL OF CHROMATOGRAPHY, 1985, 330 (01): : 1 - 17
  • [48] INVESTIGATION OF OPERATING PARAMETERS IN HIGH-PERFORMANCE DISPLACEMENT CHROMATOGRAPHY
    HORVATH, C
    FRENZ, J
    VANDERSCHRIECK, P
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 1985, 189 (APR-): : 98 - ANYL
  • [49] High-performance photorefractive polymer operating at 975 nm
    Eralp, M
    Thomas, J
    Tay, S
    Li, G
    Meredith, G
    Schülzgen, A
    Peyghambarian, N
    Walker, GA
    Barlow, S
    Marder, SR
    APPLIED PHYSICS LETTERS, 2004, 85 (07) : 1095 - 1097
  • [50] HIGH-PERFORMANCE SEMIINTERPENETRATING NETWORK POLYMERS
    NARAYANAN, VS
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 1986, 191 : 15 - CMEC