scieee Open visual document viewer

Optimal switch configuration in software-defined networks

Genge, Béla; Sztrik, János

Full text

Scien i ic Bulle in o he “Pe u Maio ” 8QLYHUVLW RI7 UJX0XUHú Vol. 13 (XXX) no. 1, 2016 ISSN-L 1841-9267 (P in ), ISSN 2285-438X (Online), ISSN 2286-3184 (CD-ROM) Op imal Swi ch Con igu a ion in So wa e-De ined Ne wo ks Béla GENGE1,János SZTRIK2 1“Pe u Maio ”Uni e si y o Tî gu Mu e¸s 1Nicolae Io ga S ee ,No. 1,540088,Tî gu Mu e¸s,Romania 1e-mail: [email protected]. o 2Uni e si y o Deb ecen 2Egye em é ,No. 1,4032,Deb ecen,Hunga y 2e-mail: sz ik.j[email p o ec ed]eb.hu Abs ac The eme ging So wa e-De ined Ne wo ks (SDN) pa adigm acili a es inno a i e ap- plica ions and enables he seamless p o isioning o esilien communica ions. Ne e - heless, he ins alla ion o communica ion lows in SDN equi es ca e ul planning in o de o a oid con igu a ion e o s and o ul ill communica ion equi emen s. In his pape we p opose an app oach ha ins alls au oma ically and op imally s a ic lows in SDN swi ches. The app oach aims o selec high capaci y links and sho es pa h ou - ing, and en o ces communica ion link and swi ch capaci y limi a ions. Expe imen al esul s demons a e he e ec i eness and scalabili y o he de eloped me hodology. Keywo ds: So wa e-De ined Ne wo ks, OpenFlow, in ege linea p og amming 1 In oduc ion An eme ging pa adigm in adi ional IP ne wo ks is he eplacemen o local ou e -based decisions wi h global ou ing decision so wa e. A p ominen enable o his end is OpenFlow, a p o ocol designed o en- su e emo e access o he o wa ding pane o a ne - wo k swi ch [1]. OpenFlow sepa a es con ol om o - wa ding, enabling he implemen a ion o mo e com- plex a ic managemen echniques. Besides Open- Flow, a key ad ancemen in he ield is he So wa e- De ined Ne wo ks (SDN) pa adigm. SDN p o ides he means o c ea e i ual ne wo king se ices and o im- plemen global ne wo king decisions. SDN elies on OpenFlow o enable communica ions wi h emo e de- ices and i is conside ed o e olu ionize he way de- cisions a e implemen ed in swi ches and ou e s. Despi e i s indispu able ad an ages, i should be no ed ha SDN is an eme ging pa adigm and i s un- de s anding, bene i s, bu mos impo an ly i s disad- an ages equi e ca e ul examina ion. While se e al s udies ha e e ealed ha SDN may indeed enhance he esilience o communica ion ne wo ks, especially in he indus ial sec o [2, 3], he p o isioning o com- munica ion lows in SDN swi ches equi es ca e ul planning o a oid con igu a ion e o s and o ul ill communica ion equi emen s. To his end, communi- ca ion lows, he eina e called simply lows, may be subjec o a ious equi emen s including Quali y o Se ice (QoS) pe aining o eal- ime packe deli e y, secu i y equi emen s, e.g., he p esence o in usion de ec ion sys ems (IDS), eliabili y o communica ion pa hs. Besides hese aspec s, he p o isioning o com- munica ion lows needs o accoun o he ha dwa e limi a ions o communica ion lines and SDN swi ches. These may signi ican ly limi he capaci y o links, and he maximum numbe o ules ha may be ins alled in SDN swi ches. This pape alle ia es he a o emen ioned issues by de eloping an app oach ha au oma ically and op i- mally ins all lows in SDN swi ches. The app oach le e ages an op imiza ion p oblem ha aims o ins all lows on he highes capaci y links and using he sho - es pa h ou ing. Subsequen ly, he p oblem encapsu- la es se e al cons ain s ha ensu e ha capaci y limi- a ions a e sa is ied. Besides hese aspec s, he me hodology emb aces c 2016 Published by ”Pe u Maio ” Uni e si y P ess. This is an open access a icle unde he CC BY-NC-ND license (h p://c ea i ecommons.o g/licenses/by-nc-nd/4.0/). 25 Py hon so wa e modules ha call he Sol ing Con- s ain In ege P og ams ool o de i e an op imal so- lu ion, and o con igu e he SDN swi ches by means o he Floodligh SDN con olle . The emaining o his wo k is s uc u ed as ollows. Sec ion 2 p o ides a b ie o e iew o ela ed s udies. Sec ion 3 p esen s he de eloped SDN swi ch con ig- u a ion me hodology, while Sec ion 4 p o ides he ex- pe imen al esul s. The pape concludes in Sec ion 5. 2 Rela ed wo k Se e al ecen s udies demons a ed he bene i s o SDN-enabled communica ion in as uc u es and iden i ied key challenges in adop ing his eme ging echnology. Yonghong Fu e al. [7] de eloped O ion, a hyb id hie a chical con ol plane o la ge-scale ne - wo ks. O ion de ines h ee planes: he domain physi- cal ne wo k, he ie 0 con ol plane consis ing o a ea con olle s, and he ie 1 con ol plane consis ing o a dis ibu ed se o domain con olle s. Tunce e al. [8] de eloped an SDN-based managemen and con ol amewo k o backbone ne wo ks. The app oach ol- lowed a hie a chical and modula s uc u e o suppo la ge-scale opologies and he simple in eg a ion o a ious managemen applica ions. The wo k o Tunce also p oposed a ne wo k planning algo i hm based on he uncapaci a ed acili y loca ion p oblem. In [9] he au ho s de eloped Dionysus, a sys em o consis en ne wo k upda es in SDN. Dionysus builds he g aph o ne wo k upda e dependencies and schedules hese up- da es by aking in o accoun he pe o mances o ne - wo k swi ches. To elimina e packe losses [10] p o- posed zUpda e, a solu ion ha uses packe labeling o ze o packe losses du ing ne wo k upda es. In com- pa ison o hese wo ks, his wo k places an emphasis on he op imal con igu a ion o SDN ne wo ks. I is aimed a deli e ing a s a ing poin , which may hen be adop ed in he de elopmen o mo e complex ne - wo k design p oblems. 3 De eloped app oach This sec ion p esen s he de eloped SDN con igu a- ion me hodology. I s a s wi h an o e iew on he de- eloped me hodology and i con inues wi h a desc ip- ion o he ne wo k con igu a ion p oblem and o he de eloped so wa e. 3.1 O e iew The a chi ec u al o e iew o he me hodology de- eloped in his pape is depic ed in Figu e 1. As shown in his igu e, he me hodology comp ises o h ee main componen s. Fi s , he SDN con igu a ion so - wa e, i.e., he main con ibu ion o his wo k, which glues oge he he emaining componen s. This ool Ne wo k desc ip ion (XML) SDN Con igu a ion So wa e Op imiza ion p oblem desc ip ion (LP) Solu ion Figu e 1. A chi ec u al o e iew o he de eloped SDN con igu a ion me hodol- ogy. akes a ne wo k desc ip ion gi en in XML o ma and au oma ically gene a es a Linea P og amming (LP) desc ip ion o he ne wo k design p oblem. Once a so- lu ion is p o ided by he ex e nal Sol ing Cons ain In ege P og ams (SCIP) ool [6], he SDN con igu a- ion so wa e akes he solu ion and sends he new ne - wo k opology o he Floodligh con olle [5]. In u n, he Floodligh con olle uses he OpenFlow p o ocol o ins all s a ic lows on SDN swi ches. 3.2 Ne wo k model We assume a demand ma ix o lows ou ed be- ween access and eg ess swi ches. The ou ing needs o be pe o med in such a way o educe communi- ca ion delays by means o selec ing he sho es pa hs and he la ges capaci y links. Flows a e assumed o be non-bi u ca ed mul icommodi y lows such ha each low can only be ou ed on one pa h. The unde aken app oach ins alls lows ac oss an SDN pool o swi ches by means o an SDN con olle , e.g., Floodligh . Flows a e ins alled on each swi ch as s a ic lows, which means ha he ou ing ule o each low does no change dynamically. Acco dingly, i is impo an o iden i y he le el o g anula i y o he de ini ion o a communica ion low, in o de o deli e an e ec i e s a egy agains malicious a - ic. Fo example, by de ining a low be ween IP ad- d esses 10.1.1.0/24 and 10.2.1.0/24 all he IP-based p o ocols, e.g., UDP, TCP, will be pe mi ed and ou ed ac oss he SDN be ween all he hos s lo- ca ed in he wo ne wo ks. Howe e , in he case ha 26 an a acke ini ia es a new low be ween wo hos s lo- ca ed in he a o emen ioned ne wo ks, his malicious a ic will also be pe mi ed. Consequen ly, a mo e app op ia e con igu a ion would de ine a communica- ion low inco po a ing he sou ce and des ina ion IP add esses, he sou ce and des ina ion MAC add esses, and he p o ocol ype. This would educe he se o hos s om which he a acke could gene a e a new communica ion low. Ob iously, in he case ha he a acke has su - icien knowledge on he ne wo k, he/she could ex- ploi he pe mi ed p o ocols and hei ulne abili ies o achie ing his/he goals. The e o e, i needs o be no ed ha he de eloped me hodology ep esen s a i s le el o de ense agains a acke s. Ne e he- less, p e ious wo k demons a ed ha low whi elis - ing can be an e ec i e coun e measu e o blocking speci ic malwa e ea u es. Mo e speci ically in [11] an expe imen was conduc ed wi h he S uxne malwa e [12, 13]. A ne wo k wi h ou hos s unning Windows XP SP2 was con igu ed and one o he hos s was de- libe a ely in ec ed wi h he S uxne malwa e. S uxne exploi ed ulne abili y MS08-067 in he SMB p o o- col (used in ile sha ing) o copy i sel on o ano he s a ion. In he case ha his SMB a ic is whi elis ed, hen S uxne can success ully eplica e i sel . How- e e , [11] also showed ha once i in ec ed a hos , S uxne also s a ed o ini ia e connec ions owa ds www.windowsupda e.com and www.msn.com ( o es In e ne connec i i y). In he case ha his a - ic is no whi elis ed, i is blocked and consequen ly, S uxne ( oge he wi h o he simila malwa e) will no be able o con ac i s Command and Con ol se e s. 3.3 Con igu a ion p oblem The ne wo k con igu a ion p oblem’s pa ame e s a e depic ed in Figu e 2. We de ine I o be he se o lows and J o be he se o swi ches. Le dideno e he demand o low iand ujl he capaci y o link (j, l), whe e j, l ∈J. We assume ha i swi ches jand l a e no connec ed, hen ujl = 0. Then, le xA ij be a bina y pa ame e wi h alue 1 i he access end-poin o low iis connec ed o swi ch j, and xE ji a bina y pa- ame e wi h alue 1 i he eg ess end-poin o low i is connec ed o swi ch j. Then, we de ine sj o be he capaci y o swi ch jin e ms o he maximum numbe o suppo ed o wa ding ules ha may be ins alled. Las ly, we de ine i jl, a bina y a iable wi h alue 1 i low iis ou ed on link (j, l). The solu ion o he p oblem will se he alues o i jl in he case ha low iis selec ed o ou ing be ween swi ches jand l(see Figu e 3). The p oblem’s objec i e is o selec he sho es ou ing pa h o each low, while selec ing he links ujl di di di di di+1 di+1 di+1 di+1 ujl ujl ujl xAij xEji sj sj sj sj sj xAij xEji Figu e 2. The op imiza ion p oblem’s pa- ame e s. ijl ijl ijl ijl ijl Figu e 3. The op imiza ion p oblem’s a iables. wi h he la ges capaci ies: min X j,l∈J 1 ujl X i∈I di i jl!.(1) The op imiza ion is subjec o he ollowing con- s ain s. Cons ain s (2) deno e classical mul icom- modi y low conse a ion cons ain s: xA ij −xE ji −X l∈J i jl − i lj= 0,∀j∈J, i ∈I. (2) Equa ions (3) a e capaci y cons ain s used o en- su e ha he link capaci y is no exceeded: X i∈I di i jl ≤ujl,∀j, l ∈J. (3) Las ly, we de ine he swi ch capaci y cons ain s o ensu e ha he maximum numbe o o wa ding ules ins alled in swi ch jdoes no exceed he swi ch capac- i y: X i∈I,l∈J i jl +X i∈I xE ji ≤sj,∀j∈J. (4) 27 Table 1. Ne wo k design p oblem sol e ime. Swi ches Flows Time[ms] 5 20 12 10 20 21 20 20 35 20 50 84 20 100 231 Table 2. Communica ion low ins alla ion ime. Flows Time[ms] 5 16 20 51 80 176 3.4 SDN con igu a ion so wa e The SDN con igu a ion so wa e is w i en in he Py hon language and comp ises o h ee main mod- ules. The Ne wo kTopology module p ocesses he ne - wo k desc ip ion p o ided as an XML ile and i builds an in e nal ep esen a ion o he ne wo k opology. The ModelSol e gene a es an LP desc ip ion o he ne wo k design p oblem, i calls he ex e nal SCIP ool, and i p ocesses he solu ion. Las ly, he Con- olle implemen s Floodligh ’s REST API and sends o he ex e nal con olle he lows ha need o be in- s alled on he SDN swi ches. 4 Resul s We pe o med se e al es s in o de o assess he pe o mance o he de eloped app oach. Acco dingly, we measu ed he ime o sol ing he op imiza ion p oblem and he ime o ins alling lows. The es s ha e been pe o med on an emula ed ne wo k opol- ogy ec ea ed wi h he Minine ne wo k emula o [4] on Ubun u LTS 14.04.3 64-bi OS, and a hos wi h Pen ium Dual Co e 3.00GHz CPU and 4GB o mem- o y. A i s , we measu ed he ime in which SCIP sol ed he ne wo k design p oblems o a ious sizes (see Table 1). Acco dingly, o a ne wo k opology in- cluding 5 swi ches and 20 lows he sol e execu es in 12ms. This inc eases up o 21ms o 10 swi ches and o 35ms o 20 swi ches. On he o he hand, by se ing a ixed numbe o swi ches o 20 and by in- c easing he numbe o lows o 50, we also measu e a mo e inc eased sol e ime o 84ms. By u he in- c easing he size o he p oblem up o 100 lows, we measu e a 231ms sol e ime. Nex , we measu ed he low ins alla ion ime (see Table 2). Acco dingly, o 5 lows he ins alla ion ime is comple ed in 16ms, o 20 lows in 51ms, while o 80 lows in 176ms. These e- sul s show ha he ne wo k p oblem sol e ime and he low ins alla ion ime exhibi a linea beha io , which is signi ican e idence o he scalabili y o he de el- oped me hodology. Ne e heless, i should be no ed ha he app oach may be u he ex ended wi h addi- ional cons ain s and pa ame e s in o de o cap u e mo e pa icula aspec s o communica ion ne wo ks om di e en domains. 5 Conclusion We de eloped a me hodology o au oma ically and op imally con igu e SDN ne wo ks. The app oach ac- coun s o he selec ion o maximum capaci y links, o he selec ion o sho es ou ing pa hs, o he ca- paci y and he limi a ions o links and SDN swi ches. As a esul , he de eloped me hodology can sa e ime and i can assis he con igu a ion o SDN ne wo ks. None heless, he ne wo k design p oblem should be seen as a s a ing poin o o he and mo e complex ne wo k con igu a ion p oblems. Acco dingly, he me hodology and mo e speci ically, he de eloped op- imiza ion p oblem, may be ex ended wi h addi ional pa ame e s and cons ain s in o de o emb ace he pa - icula i ies o di e en scena ios and domains. Acknowledgmen This esea ch was suppo ed by he Hun- ga ian Academy o Sciences unde g an no. 6611/10/2015/HTMT. Re e ences [1] N. McKeown, T. Ande son, G. Pa ulka , L. Pe- e son, J. Rex o d, S. Shenke and J.Tu ne , OpenFlow: Enabling inno a ion in campus ne - wo ks, ACM SIGCOMM Compu e Communi- ca ion Re iew, ol. 38(2), pp. 69–74, 2008. [2] A. Goodney, S. Kuma , A. Ra i and Y.Cho, E - icien PMU ne wo king wi h so wa e-de ined ne wo ks, P oceedings o he Fou h IEEE In e - na ional Con e ence on Sma G id Communica- ions, pp. 378–383, 2013. [3] E. Molina, E. Jacob, J. Ma ias, N.Mo ei a and A. As a loa, Using so wa e-de ined ne wo king o manage and con ol IEC 61850 based sys ems, Compu e s and Elec ical Enginee ing, ol. 43, pp. 142-154, 2015. [4] N. Handigol, B. Helle , V. Jeyakuma , B. Lan z and N. McKeown, Rep oducible ne wo k expe - imen s using con aine -based emula ion, in P o- ceedings o he 8 h In e na ional Con e ence on 28 Eme ging Ne wo king Expe imen s and Tech- nologies, (New Yo k, NY, USA), pp. 253-264, ACM, 2012. [5] P ojec Floodligh , h p://www. p ojec loodligh .o g/ loodligh / [Online; accessed Ap il 2016]. [6] T. Ach e be g, Scip: sol ing cons ain in ege p og ams, Ma hema ical P og amming Compu- a ion, ol. 1(1), pp. 1-41, 2009. [7] Y. Fu, J. Bi, Z. Chen, K. Gao, B. Zhang, G. Chen, and J. Wu, A hyb id hie a chical con ol plane o low-based la ge-scale so wa e-de ined ne - wo ks, IEEE T ansac ions on Ne wo k and Se - ice Managemen , ol. 12, pp. 117-131, June 2015. [8] D. Tunce , M. Cha alambides, S. Clayman, and G. Pa lou, Adap i e esou ce managemen and con ol in so wa e de ined ne wo ks, IEEE T ansac ions on Ne wo k and Se ice Manage- men , ol. 12, pp. 18-33, Ma ch 2015. [9] X. Jin, H. H. Liu, R. Gandhi, S. Kandula, R. Mahajan, M. Zhang, J. Rex o d and R. Wa en- ho e , Dynamic scheduling o ne wo k upda es, SIGCOMM Compu e Communica ions Re iew, ol. 44, pp. 539-550, Augus 2014. [10] H. H. Liu, X. Wu, M. Zhang, L. Yuan, R. Wa en- ho e and D. Mal z, zupda e: Upda ing da a cen- e ne wo ks wi h ze o loss, SIGCOMM Com- pu e Communica ions Re iew, ol. 43, pp. 411- 422, Augus 2013. [11] B. Genge, D.A. Rusu, and P. Halle : A Con- nec ion Pa e n-based App oach o De ec Ne - wo k T a ic Anomalies in C i ical In as uc- u es. 2014 ACM Eu opean Wo kshop on Sys- em Secu i y (Eu oSec2014), Ams e dam, The Ne he lands, pp. 1-6, 2014. [12] M. Hage o : S uxne and he i al ole o c i i- cal in as uc u e ope a o s and enginee s. In e - na ional Jou nal o C i ical In as uc u e P o ec- ion, ol. 7(4):244-246, 2014. [13] B. Genge, F. G au , and P. Halle : Expe imen- al Assessmen o Ne wo k Design App oaches o P o ec ing Indus ial Con ol Sys ems, In e - na ional Jou nal o C i ical In as uc u e P o ec- ion, ol. 11, pp. 24-38, 2015. 29 Copy igh o Scien i icBulle ino hePe uMaio Uni e si yo Ta guMu esis hep ope y o Pe uMaio Uni e si yo Tî gu-Mu esandi scon en mayno becopiedo emailed o mul iplesi eso pos ed oalis se wi hou hecopy igh holde 'sexp essw i enpe mission. Howe e ,use smayp in ,download,o emaila icles o indi idualuse.