计算机科学 ›› 2024, Vol. 51 ›› Issue (2): 311-321.doi: 10.11896/jsjkx.221100196
肖肇斌1,2,3, 崔允贺1,2,3, 陈意1,2,3, 申国伟1,2,3, 郭春1,2,3, 钱清4
XIAO Zhaobin1,2,3, CUI Yunhe1,2,3, CHEN Yi1,2,3, SHEN Guowei1,2,3, GUO Chun1,2,3, QIAN Qing4
摘要: 网络遥测是一种新型的网络测量技术,具有实时性强、准确性高、开销低的特点。现有网络遥测技术存在无法收集多粒度网络数据、无法有效存储大量原始网络数据、无法快速提取及生成网络遥测信息、无法利用内核态及用户态特性设计网络遥测方案等问题。为此,提出了一种融合内核态及用户态的、基于遥测数据图和同步控制块的多粒度、可扩展、覆盖全网的网络遥测机制(a nEtwork telemetry mechAnism based on telemetry data Graph in kerneL and usEr mode,EAGLE)。EAGLE设计了一种能够收集多粒度数据且数据平面上灵活可控的网络遥测数据包结构,用于获取上层应用所需的数据。此外,为快速存储、查询、统计、聚合网络状态数据,实现网络遥测数据包所需遥测数据的快速提取与生成,EAGLE提出了一种基于遥测数据图及同步控制块的网络遥测信息生成方法。在此基础上,为了最大化网络遥测机制中网络遥测数据包的处理效率,EAGLE提出了融合内核态及用户态特性的网络遥测信息嵌入架构。在Open vSwitch上实现了EAGLE方案并进行了测试,测试结果表明,EAGLE能够收集多粒度数据并快速提取与生成遥测数据,且仅增加极少量的处理时延及资源占用率。
中图分类号:
[1]GULENKO A,WALLSCHLÄGER M,KAO O.A practical implementation of in-band network telemetry in open vswitch[C]//2018 IEEE 7th International Conference on Cloud Networking(CloudNet).IEEE,2018. [2]MCKEOWN N,ANDERSON T,BALAKRISHNAN H,et al.OpenFlow:enabling innovation in campus networks[J].ACM SIGCOMM Computer Communication Review,2008,38(2):69-74. [3]ZHANG H,CAI Z,LIU Q,et al.A survey on security-aware measurement in SDN[J/OL].https://www.hindawi.com/journals/scn/2018/2459154/. [4]PENG G B,CHEN M,BAI Y.Analysis of SDN Attack and Defense Technology [J].Information Security Research,2019,5(4):333. [5]CAI Z,WANG Z,ZHENG K,et al.A distributed TCAM coprocessor architecture for integrated longest prefix matching,policy filtering,and content filtering[J].IEEE Transactions on Computers,2011,62(3):417-427. [6]PHAAL P,PANCHEN S,MCKEE N.InMon corporation’ssFlow:A method formonitoring traffic in switched and routed networks[EB/OL].https://www.rfc-editor.org/info/rfc3176. [7]QUITTEK J,ZSEBY T,CLAISE B,et al.Requirements for IP flow information export(IPFIX)[EB/OL].https://www.rfc-editor.org/info/rfc3917. [8]SOMMER R,FELDMANN A.NetFlow:Information loss orwin? [C]//Proceedings of the 2nd ACM SIGCOMM Workshop on Internet Measurment.2002:173-174. [9]CLAISE B,JOHNSON A,QUITTEK J.Packet sampling(PSAMP) protocol specifications[EB/OL].https://www.rfc-editor.org/info/rfc5476. [10]TAN L,SU W,ZHANG W,et al.In-band network telemetry:A survey[J].Computer Networks,2021,186:107763. [11]KIM C,SIVARAMAN A,KATTA N,et al.In-band networktelemetry via programmable dataplanes[C]//ACM SIGCOMM Industrial Demo Session.2015. [12]LIU ZZ,BI J,ZHOU Y,et al.Active network telemetry mechanism based on P4 [J].Journal of Communications,2018,39(A1):162-169. [13]RAMANATHAN S,KANZA Y,KRISHNAMURTHY B.SDProber:A software defined prober for SDN[C]//Proceedings of the Symposium on SDN Research.2018. [14]ZHOU Y,SUN C,LIU H H,et al.Flow event telemetry on programmable data plane[C]//Proceedings of the Annual Confe-rence of the ACM Special Interest Group on Data Communication on the Applications,Technologies,Architectures,and Protocols for Computer Communication.2020:76-89. [15]HUANG Q,SUN H,LEE P P C,et al.Omnimon:Re-architecting network telemetry with resource efficiency and full accuracy[C]//Proceedings of the 2020 Annual Conference of the ACM Special Interest Group on Data Communication on the Applications,Technologies,Architectures,and Protocols for Computer Communication.2020:404-421. [16]PAN T,LIN X C,ZHANG J,et al.In-band network telemetry system based on high-performance packet processing architecture VPP[J].Journal of Communications,2021,42(3):75-90. [17]FEZEU R A K,ZHANG Z L.Anomalous Model-Driven-Tele-metry Network-Stream BGP Detection[C]//2020 IEEE 28th International Conference on Network Protocols(ICNP).IEEE,2020. [18]BEN BASAT R,RAMANATHAN S,LI Y,et al.PINT:Probabilistic in-band network telemetry[C]//Proceedings of the 2020 Annual Conference of the ACM Special Interest Group on Data Communication on the Applications,Technologies,Architectures,and Protocols for Computer Communication.2020:662-680. [19]NAM S,LIM J,YOO J H,et al.Network anomaly detectionbased on in-band network telemetry with RNN[C]//2020 IEEE International Conference on Consumer Electronics-Asia(ICCE-Asia).IEEE,2020. [20]PFAFF B,PETTIT J,KOPONEN T,et al.The Design and Implementation of Open vSwitch[C]//12th USENIX Symposium on Networked Systems Design and Implementation(NSDI 15).2015:117-130. [21]YUAN X,MAHAPATRA S,NIENABER W,et al.A new routing scheme for Jellyfish and its performance with HPC workloads[C]//Proceedings of the International Conference on High Performance Computing,Networking,Storage and Analysis.2013. [22]CUI Y,YAN L,LI S,et al.SD-Anti-DDoS:Fast and efficient DDoS defense in software-defined networks[J].Journal of Network and Computer Applications,2016,68:65-79. |
|