Next-generation mobile core networks are required to be scalable and capable of efficiently utilizing heterogeneous bare metal resources that may include edge servers. To this end, microservice-based solutions where control plane procedures are deconstructed in their fundamental building blocks are gaining momentum. This letter proposes an optimization framework delivering the partitioning and mapping of large-scale microservice graphs onto heterogeneous bare metal deployments while minimizing the total network traffic among servers. An efficient heuristic strategy for solving the optimization problem is also provided. Simulation results show that, with the proposed framework, a microservice-based core can consistently support the requested load in heterogeneous bare metal deployments even when alternative architecture fails. Besides, our framework ensures an overall reduction in the control plane-related network traffic if compared to current core architectures.
To automate network operations and deployment of compute services, intent-driven service management (IDSM) is essential. It enables network users to express their service requirements in a declarative manner as intents. To fulfill the intents, closed control-loop operations carry out required configurations and deployments without human intervention. Despite the fact that intents are fulfilled automatically, conflicts may arise between user’s and service provider’s intents due to limited resources availability. This triggers IDSM system to initialize an intent negotiation process among conflicting actors. Intent negotiation involves generating one or more alternate intents based on the current state of the underlying physical/virtual resources, which are then presented to the intent creator for acceptance or rejection. In this way, the quality of services (QoS) can be improved significantly by maximizing the acceptance rate of service requests in the scenario of limited resources. However, intent negotiation systems are still in their infancy. The available solutions are platform dependent which poses various challenges in their adoption to diverse platforms. The main focus of this work is to draft and evaluate a comprehensive and generic intent negotiation framework which can be used to develop intent ne- gotiation solutions for diverse IDSM platforms. In this work, we have identified and defined various processes that are necessary for intent negotiation. Furthermore, a generic intent negotiation framework is presented representing interactions among the identified processes, while conflicting actors engage in the intent negotiation. The results demonstrated that the proposed intent negotiation framework increases the intent acceptance rate by up to 38% with processing overheads less than 10%.
Traditional, slow and error-prone human-driven methods to configure and manage Internet service requests are proving unsatisfactory. This is due to an increase in Internet applications with stringent quality of service (QoS) requirements. Which demands faster and fault-free service deployment with minimal or without human intervention. With this aim, intent-driven service management (IDSM) has emerged, where users express their service level agreement (SLA) requirements in a declarative manner as intents . With the help of closed control-loop operations, IDSM performs service configurations and deployments, autonomously to fulfill the intents. This results in a faster deployment of services and reduction in configuration errors caused by manual operations, which in turn reduces the SLA violations. This article is an attempt to provide a systematic review of How the IDSM systems manage and fulfill the SLA requirements specified as intents. As an outcome, the review identifies four intent management activities, which are performed in a closed-loop manner. For each activity, a taxonomy is proposed and used to compare the existing techniques for SLA management in IDSM systems. A critical analysis of all the considered research articles in the review and future research directions are presented in the conclusion.
The emergence of Network Functions Virtualization (NFV) is being heralded as an enabler of the recent technologies such as 5G/6G, IoT and heterogeneous networks. Existing NFV monitoring frameworks either do not have the capabilities to express the range of telemetry items needed to perform management or do not scale to large traffic volumes and rates. We present IntOpt, a scalable and expressive telemetry system designed for flexible NFV monitoring using active probing and P4. IntOpt allows us to specify monitoring requirements for individual service chain, which are mapped to telemetry item collection jobs that fetch the required telemetry items from P4 programmable data-plane elements. We propose mixed integer linear program (MILP) as well as a simulated annealing based random greedy (SARG) meta-heuristic approach to minimize the overhead due to active probing and collection of telemetry items. Using P4-FPGA, we benchmark the overhead for telemetry collection. Our numerical evaluation shows that the proposed approach can reduce monitoring overheads by 39% and monitoring delays by 57%. Such optimization may as well enable existing expressive monitoring frameworks to scale for larger real-time networks.
Network Function Virtualization (NFV) is an emerging technology to consolidate network functions onto high volume storages, servers and switches located anywhere in the network. Virtual Network Functions (VNFs) are chained together to provide a specific network service, called Service Function Chains (SFCs). Regarding to Quality of Service (QoS) requirements and network features and states, SFCs are served through performing two tasks: VNF placement and link embedding on the substrate networks. Reducing deployment cost is a desired objective for all service providers in cloud/edge environments to increase their profit form demanded services. However, increasing resource utilization in order to decrease deployment cost may lead to increase the service latency and consequently increase SLA violation and decrease user satisfaction. To this end, we formulate a multi-objective optimization model to joint VNF placement and link embedding in order to reduce deployment cost and service latency with respect to a variety of constraints. We, then solve the optimization problem using two heuristic-based algorithms that perform close to optimum for large scale cloud/edge environments. Since the optimization model involves conflicting objectives, we also investigate pareto optimal solution so that it optimizes multiple objectives as much as possible. The efficiency of proposed algorithms is evaluated using both simulation and emulation. The evaluation results show that the proposed optimization approach succeed in minimizing both cost and latency while the results are as accurate as optimal solution obtained by Gurobi (5%).
Industrial Control System (ICS) is a general term that includes supervisory control & data acquisition (SCADA) systems, distributed control systems (DCS), and other control system configurations such as programmable logic controllers (PLC). ICSs are often found in the industrial sectors and critical infrastructures, such as nuclear and thermal plants, water treatment facilities, power generation, heavy industries, and distribution systems. Though ICSs were kept isolated from the Internet for so long, significant achievable business benefits are driving a convergence between ICSs and the Internet as well as information technology (IT) environments, such as cloud computing. As a result, ICSs have been exposed to the attack vectors used in the majority of cyber-attacks. However, ICS devices are inherently much less secure against such advanced attack scenarios. A compromise to ICS can lead to enormous physical damage and danger to human lives. In this work, we have a close look at the shift of the ICS from stand-alone systems to cloud-based environments. Then we discuss the major works, from industry and academia towards the development of the secure ICSs, especially applicability of the machine learning techniques for the ICS cyber-security. The work may help to address the challenges of securing industrial processes, particularly while migrating them to the cloud environments.
In-Band Network Telemetry (INT) is a novel framework for collecting telemetry items and switch internal state information from the data plane at line rate.With the support of programmable data planes and programming language P4, switches parse telemetry instruction headers and determine which telemetry items to attach using custom metadata.At the network edge, telemetry information is removed and the original packets are forwarded while telemetry reports are sent to a distributed stream processor for further processing by a network monitoring platform.In order to avoid excessive load on the stream processor, telemetry items should not be sent for each individual packet but rather when certain events are triggered.In this paper, we develop a programmable INT event detection mechanism in P4 that allows customization of which events to report to the monitoring system, on a per-flow basis, from the control plane.At the stream processor, we implement a fast INT report collector using the kernel bypass technique AF XDP, which parses telemetry reports and streams them to a distributed Kafka cluster, which can apply machine learning, visualization and further monitoring tasks.In our evaluation, we use realworld traces from different data center workloads and show that our approach is highly scalable and significantly reduces the network overhead and stream processor load due to effective event pre-filtering inside the switch data plane.While the INT report collector can process around 3 Mpps telemetry reports per core, using event pre-filtering increases the capacity by 10-15x.
Network Function Virtualization (NFV) is an emerging technology to consolidate network functions onto high volume storages, servers and switches located anywhere in the network. Virtual Network Functions (VNFs) are chained together to provide a specific network service. Therefore, an effective service chain placement strategy is required to optimize the resource allocation and consequently to reduce the operating cost of the substrate network. To this end, we propose four genetic-based algorithms using roulette wheel and tournament selection techniques in order to place service chains considering two different placement strategies. Since mapping of service chains sequentially (One-at-a-time strategy) may lead to suboptimal placement, we also propose Simultaneous strategy that places all service chains at the same time to improve performance. Our goal in this work is to reduce deployment cost of VNFs while satisfying constraints. We consider Geant network as the substrate network along with its characteristics extracted from SndLib. The proposed algorithms are able to place service chains with any type of service graph. The performance benefits of the proposed algorithms are highlighted through extensive simulations.
Cloud computing is gaining significant traction and virtualized data centers are becoming popular as a cost-effective infrastructure in telecommunication industry. Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS) are being widely deployed and utilized by end users, including many private as well as public organizations. Despite its wide-spread acceptance, security is still the biggest threat in cloud computing environments. Users of cloud services are under constant fear of data loss, security breaches, information theft and availability issues. Recently, learning-based methods for security applications are gaining popularity in the literature with the advents in machine learning (ML) techniques. In this work, we explore applicability of two well-known machine learning approaches, which are, Artificial Neural Networks (ANN) and Support Vector Machines (SVM), to detect intrusions or anomalous behavior in the cloud environment. We have developed ML models using ANN and SVM techniques and have compared their performances. We have used UNSW-NB-15 dataset to train and test the models. In addition, we have performed feature engineering and parameter tuning to find out optimal set of features with maximum accuracy to reduce the training time and complexity of the ML models. We observe that with proper features set, SVM and ANN techniques have been able to achieve anomaly detection accuracy of 91% and 92% respectively, which is higher compared against that of the one achieved in the literature, with reduced number of features needed to train the models.
Carriers' network services are distributed, dynamic, and investment intensive. Deploying them as virtual network services (VNS) brings the promise of low-cost agile deployments, which reduce time to market new services. If these virtual services are hosted dynamically over multiple clouds, greater flexibility in optimizing performance and cost can be achieved. On the flip side, when orchestrated over multiple clouds, the stringent performance norms for carrier services become difficult to meet, necessitating novel and innovative placement strategies. In selecting the appropriate combination of clouds for placement, it is important to look ahead and visualize the environment that will exist at the time a virtual network service is actually activated. This serves multiple purposes - clouds can be selected to optimize the cost, the chosen performance parameters can be kept within the defined limits, and the speed of placement can be increased. In this paper, we propose the P-ART (Predictive-Adaptive Real Time) framework that relies on predictive-deductive features to achieve these objectives. With so much riding on predictions, we include in our framework a novel concept-drift compensation technique to make the predictions closer to reality by taking care of long-term traffic variations. At the same time, near real-time update of the prediction models takes care of sudden short-term variations. These predictions are then used by a new randomized placement heuristic that carries out a fast cloud selection using a least-cost latency-constrained policy. An empirical analysis carried out using datasets from a queuing-theoretic model and also through implementation on CloudLab, proves the effectiveness of the PART framework. The placement system works fast, placing thousands of functions in a sub-minute time frame with a high acceptance ratio, making it suitable for dynamic placement. We expect the framework to be an important step in making the deployment of carrier-grade VNS on multi-cloud systems, using network function virtualization (NFV), a reality.
Network Function Virtualization (NFV) with minimum-delay service function chains will be a key enabling technology for next generation mobile networks, such as 5G. In this paper, we present a new approach to generate problem instances for the cost optimized delay sensitive Virtualized Network Function (VNF) placement and routing problem, where we know by construction the optimal solution for the given objective function. Our approach produces problem instances, which can be used to test and benchmark heuristic algorithms against. We then implement an Affinity based simulated annealing (ABSA) heuristic approach for cost optimized delay aware placement of VNFs along with a set of greedy approaches. We evaluate the implemented approaches against the optimal solution by generating several problem instances using our proposed method.
With the enhancements in the field of software‐defined networking and virtualization technologies, novel networking paradigms such as network function virtualization and the Internet of Things are rapidly gaining ground. The development of Internet of Things and 5G networks and explosion in online services has resulted in an exponential growth of devices connected to the network. As a result, application service providers and Internet service providers are being confronted with the unprecedented challenge of accommodating increasing service and traffic demands from the geographically distributed users. To tackle this problem, many and ISPs, such as Netflix, Facebook, and AT&T, are increasingly adopting microservices application architecture. Despite the success of microservices in the industry, there is no specific standard or research work for service providers as guidelines, especially from the perspective of basic microservice operations. In this work, we aim to bridge this gap between the industry and the academia and discuss different microservice deployment, discovery, and communication options for service providers as a means to forming complete service chains. In addition, we address the problem of scheduling microservices across multiple clouds, including microclouds. We consider different user‐level service level agreements, such as latency and cost, while scheduling such services. We aim to reduce the overall turnaround time and costs for the deployment of complete end‐to‐end service. In this work, we present a novel affinity‐based fair weighted scheduling heuristic to solve this problem. We also compare the results of the proposed solution with standard greedy scheduling algorithms presented in the literature and observe significant improvements.
Traditionally, in cellular networks, users communicate with the base station that serves the particular cell under coverage. The main functions of a base station can be divided into two, which are the baseband unit (BBU) functionalities and the remote radio head (RRH) functionalities. The RRH module is responsible for digital processing, frequency filtering and power amplification. The main sub-functions of the baseband processing module are coding, modulation, Fast Fourier Transform (FFT) and others. Data generally flows from RRH to BBU for further processing. Such BBU functionalities may be shifted to the cloud based resource pool, called as the Cloud-Radio Access Network (C-RAN) to be shared by multiple RRHs. Advancements in the field of cloud computing, software defined networking and virtualization technology may be leveraged by operators for the deployment of their BBU services, reducing the total cost of deployment. Recently, there has been a trend to collocate the baseband unit (BBU) functionalities and services from multiple cellular base stations into a centralized BBU pool for the statistical multiplexing gains. The technology is known as Cloud Radio Access Network (C-RAN). C-RAN is a novel mobile network architecture that can address a number of challenges the mobile operators face while trying to support the growing end users’ needs. The idea is to virtualize the BBU pools, which can are shared by different cellular network operators, allowing them to rent radio access network (RAN) as a cloud service. However, the manual configuration of the BBU services over the virtualized infrastructure may be inefficient and error-prone with the increasing mobile traffic. Similarly, in centralized BBU pools, non-optimal placement of the Virtual Functions (VFs) might result in a high deployment cost as well as long delays to the end-users. This may mitigate the advantages of this novel technology platform. Hence, the optimized placement of these VFs is necessary to reduce the total delays as well as minimize the overall cost to operate the C-RANs. Despite great advantages provided by the C-RAN architecture, there is no explicit support for the mobile operators to deploy their BBU services over the virtualized infrastructure, which may lead to the ad-hoc and error-prone service deployment in the BBU pools. Given the importance of C-RANs and yet the ad-hoc nature of their deployment, there is a need of automated and optimal application delivery in the context of cloud-based radio access networks to fully leverage the cloud computing opportunities in the Internet. In this work, we propose development of a novel automated service deployment platform, which will help to automate the instantiation of virtual machines at the cloud as user demands vary to achieve end-to-end automation in service delivery for C-RANs. Also, we consider the problem of optimal VF placement over distributed virtual resources spread across multiple clouds, creating a centralized BBU cloud. The aim is to minimize the total response time to the base stations in the network, as well as to satisfy the cost and capacity constraints. In this work, we implement an enhanced version of the two common approaches in the literature, which are: (1) branch-and-bound (BnB) and (2) Simulated Annealing (SA). The enhancement reduces the execution complexity of the BnB heuristic so that the allocation is faster. The proposed enhancements also improve the quality of the solution significantly. We compare the results of the standard BnB and SA schemes with the enhanced approaches to demonstrate these claims. Our aim was to develop a faster solution which can meet the latency requirements of the C-RANs, while the performance (here, in terms of cost and latency) is not far from the optimal. The proposed work contributes to “Information & Computing Technology” pillar of ARC’18. Also, it contributes to Qatar National Vision 2030 that encourages ICT initiatives. This vision, envisages Qatar at the forefront of the latest revolutions in computing, networking, Internet, and Mobility. Mobile applications form the majority of business applications on the Internet. This research proposal addresses the latest research issues in proliferation of the novel technology such as 5G. This project is timely since there is limited research, in Qatar (as well as globally) on supporting application delivery in general in the context of multiple heterogeneous cloud-based application deployment environments.
Cloud computing has been widely adopted by application service providers (ASPs) and enterprises to reduce both capital expenditures (CAPEX) and operational expenditures (OPEX). Applications and services previously running on private data centers are now being migrated to private or public clouds. Since most of the ASPs and enterprises have globally distributed user bases, their services need to be distributed across multiple clouds, spread across the globe which can achieve better performance in terms of latency, scalability and load balancing. The shift has eventually led the research community to study multi-cloud environments. However, the widespread acceptance of such environments has been hampered by major security concerns. Firewalls and traditional rule-based security protection techniques are not sufficient to protect user-data in multi-cloud scenarios. Recently, advances in machine learning techniques have attracted the attention of the research community to build intrusion detection systems (IDS) that can detect anomalies in the network traffic. Most of the research works, however, do not differentiate among different types of attacks. This is, in fact, necessary for appropriate countermeasures and defense against attacks. In this paper, we investigate both detecting and categorizing anomalies rather than just detecting, which is a common trend in the contemporary research works. We have used a popular publicly available dataset to build and test learning models for both detection and categorization of different attacks. To be precise, we have used two supervised machine learning techniques, namely linear regression (LR) and random forest (RF). We show that even if detection is perfect, categorization can be less accurate due to similarities between attacks. Our results demonstrate more than 99% detection accuracy and categorization accuracy of 93.6%, with the inability to categorize some attacks. Further, we argue that such categorization can be applied to multi-cloud environments using the same machine learning techniques.
The new generation of 5G mobile services place stringent requirements for cellular network operators in terms of latency and costs. The latest trend in radio access networks (RANs) is to pool the baseband units (BBUs) of multiple radio base stations and to install them in a centralized infrastructure, such as a cloud, for statistical multiplexing gains. The technology is known as Cloud Radio Access Network (CRAN). Since cloud computing is gaining significant traction and virtualized data centers are becoming popular as a cost-effective infrastructure in the telecommunication industry, CRAN is being heralded as a candidate technology to meet the expectations of radio access networks for 5G. In CRANs, low energy base stations (BSs) are deployed over a small geographical location and are connected to a cloud via finite capacity backhaul links. Baseband processing unit (BBU) functions are implemented on the virtual machines (VMs) in the cloud over commodity hardware. Such functions, built in software, are termed as virtual functions (VFs). The optimized placement of VFs is necessary to reduce the total delays and minimize the overall costs to operate CRANs. Our study considers the problem of optimal VF placement over distributed virtual resources spread across multiple clouds, creating a centralized BBU cloud. We propose a combinatorial optimization model and the use of two heuristic approaches, which are, branch-and-bound (BnB) and simulated annealing (SA) for the proposed optimal placement. In addition, we propose enhancements to the standard BnB heuristic and compare the results with standard BnB and SA approaches. The proposed enhancements improve the quality of the solution in terms of latency and cost as well as reduce the execution complexity significantly. We also determine the optimal number of clouds, which need to be deployed so that the total links delays, as well as the service migration delays, are minimized, while the total cloud deployment cost is within the acceptable limits.
Network function virtualization (NFV) over multi-cloud promises network service providers amazing flexibility in service deployment and optimizing cost. Telecommunications applications are, however, sensitive to performance indicators, especially latency, which tend to get degraded by both the virtualization and the multiple cloud requirement for widely distributed coverage. In this work we propose an efficient framework that uses the novel concept of random cloud selection combined with a support vector regression based predictive model for cost optimized latency aware placement (COLAP) of service function chains. Extensive empirical analysis has been carried out with training datasets generated using a queuing-theoretic model. The results show good generalization performance of the predictive algorithm. The proposed framework can place thousands of virtual network functions in less than a minute and has high acceptance ratio.
Cloud computing is gaining significant attention and virtualized data-centers are becoming popular as cost-effective infrastructure. Recently, there has been a trend to collocate the baseband unit (BBU) functionalities and services from multiple cellular base stations into centralized BBU pool for statistical multiplexing gain. The technology is known as Cloud Radio Access Network (C-RAN). C-RAN is a novel mobile network architecture that can address a number of challenges the mobile operators face while trying to support growing end users' needs. The idea is to virtualize BBU pools, which can be shared by different cellular network operators, allowing them to rent radio access network (RAN) as a cloud service. However, manual configuration of the BBU services over the virtualized infrastructure may be inefficient and error-prone with the increasing mobile traffic. In this work, we propose development of a novel automated service deployment platform, which will help to automate the instantiation of virtual machines at the central clouds as per user demands vary and achieve end-to-end automation in service delivery for C-RANs.
Deployment of Network Function Virtualization (NFV) over multiple clouds accentuates its advantages like flexibility of virtualization, proximity to customers and lower total cost of operation. However, NFV over multiple clouds has not yet attained the level of performance to be a viable replacement for traditional networks. One of the reasons is the absence of a standard based Fault, Configuration, Accounting, Performance and Security (FCAPS) framework for the virtual network services. In NFV, faults and performance issues can have complex geneses within virtual resources as well as virtual networks and cannot be effectively handled by traditional rule-based systems. To tackle the above problem, we propose a fault detection and localization model based on a combination of shallow and deep learning structures. Relatively simpler detection has been effectively shown to be handled by shallow machine learning structures like Support Vector Machine (SVM). Deeper structure, i.e., the stacked autoencoder has been found to be useful for a more complex localization function where a large amount of information needs to be worked through to get to the root cause of the problem. We provide evaluation results using a dataset adapted from fault datasets available on Kaggle and another based on multivariate kernel density estimation and Markov sampling.
Lately application service providers (ASPs) and Internet service providers (ISPs) are being confronted with the unprecedented challenge of accommodating increasing service and traffic demands from their geographically distributed users. Many ASPs and ISPs, such as Facebook, Netflix, AT&T and others have adopted micro-service architecture to tackle this problem. Instead of building a single, monolithic application, the idea is to split the application into a set of smaller, interconnected services, called micro-services (or simply services). Such services are lightweight and perform distinct tasks independent of each other. Hence, they can be deployed quickly and independently as user demands vary. Nevertheless, scheduling of micro-services is a complex task and is currently under-researched. In this work, we address the problem of scheduling micro-services across multiple clouds, including micro-clouds. We consider different user-level SLAs, such as latency and cost, while scheduling such services. Our aim is to reduce overall turnaround time for the complete end-to-end service in service function chains and reduce the total traffic generated. In this work we present a novel fair weighted affinity-based scheduling heuristic to solve this problem. We also compare the results of proposed solution with standard biased greedy scheduling algorithms presented in the literature and observe significant improvements.
Khaled M. Khan合作论文数Qatar University, Qatar1
Shuiguang Deng (邓水光)合作论文数College of Computer Science and Technology, Zhejiang University1