Aaron Gember-Jacobson, Chaithan Prakash, Raajay Viswanathan, Robert Grandl, Junaid Khalid, Sourav Das, Aditya Akella
1
OpenNF: Enabling Innovation in Network Function Control Aaron - - PowerPoint PPT Presentation
OpenNF: Enabling Innovation in Network Function Control Aaron Gember-Jacobson , Chaithan Prakash, Raajay Viswanathan, Robert Grandl, Junaid Khalid, Sourav Das, Aditya Akella 1 Network functions (NFs) Perform sophisticated stateful actions
1
2
Intrusion detection system (IDS) Caching proxy WAN
3
Intrusion detection system (IDS) Caching proxy WAN
Xen/KVM
4
CPU Packet loss
5
CPU Packet loss
[Stratos - arXiv:1305.0209]
[SIMPLE - SIGCOMM ‘13]
[Stratos - arXiv:1305.0209]
6
Packet loss SLA: <1%
7
… 1 2 3 …
8
9
10
11
Connection Connection TcpAnalyzer HttpAnalyzer TcpAnalyzer HttpAnalyzer
ConnCount
Statistics
12
Per Multi All
13
move (port=80, Bro1, Bro2) get(per, port=80) [Chunk1] put (per, Chunk1) del(per, port=80) [Chunk2] put (per, Chunk2) forward(port=80, Bro2)
detect- MHR
14
B1 R1 R2 R2
move(red,Bro1 ,Bro2 ) Missing updates
R3
15
R1
16
R3 R1 Drop R1 R1,R2 R2 R2 R1,R2,R3
17
Controller Switch Bro2
forwarding update Bro1
R2 R2 R4 R3 R3 R3 R2 R4 R3 R3
18
19
20
[arXiv:1305.0209]
21
Serialization/deserialization costs dominate Cost grows with state complexity
50 100 150 200 Average Maximum
Per-packet Latency Increase (ms)
100 200 300 400 500 NG NG PL LF PL+ER
Move Time (ms)
22
Packets dropped! 686 462 881 packets in events
1120 pkts buffered 838 pkts in events + Bro: 5% of alerts missed!
NG NG PL LF PL+ER OP PL+ER
23
24
25
26
27
B1 Drop B1 B1,B2 B2 B1,B2, B3 Buf B3 B3 B3 B4 B1,B2, B3,B4
28
Filter Per Multi All Scope
…
1 2 3 … …
movePrefix(prefix,oldInst,newInst): copy(oldInst,newInst,{nw_src:prefix},multi) move(oldInst,newInst,{nw_src:prefix},per,LF+OP) while (true): sleep(60) copy(oldInst,newInst,{nw_src:prefix},multi) copy(newInst,oldInst,{nw_src:prefix},multi)
scan.bro vulnerable.bro weird.bro
29
30