Inter-domain routing (IDR), in which autonomous systems (ASes) co-operate to exchange information so that packets can be forwarded to their intended destinations, is a crucial component of any global network service. IDR in today's Internet is already challenging because of the need to accommodate each AS's route selection policies. Policies are determined by business (i.e., generating revenue or increasing costs for the AS), performance, and reliability considerations. IDR for information-centric networking (ICN) services is further complicated by the scale and topology-independence of the data namespace. On the other hand, ICN approaches that offer built-in origin authenticity and integrity have potential to overcome some of the issues with the current Border Gateway Protocol-based legacy IDR system, which was originally deployed without security mechanisms. In this paper, we survey a set of representative IDR solutions for information-centric networking proposed in the literature. We describe key design aspects of such systems, and characterize the surveyed systems in terms of those aspects. We point out tradeoffs involved in minimizing network resources wasted on delivery of data that the application will consider bogus; this is important at the inter-domain level, where transit service involves compensation between ASes. Finally, we discuss the issue of trust, and identify potential research directions for IDR in the context of ICN.
Emerging new applications demand the current Internet to provide new functionalities. Although many future Internet architectures and protocols have been proposed to fulfill such needs, ISPs have been reluctant to deploy many of these architectures. We believe technical issues are not the main reasons as many of these new proposals are technically sound. In this paper, we take an economic perspective and seek to answer: Why do most new Internet architectures fail to be deployed? How can the deployability of a new architecture be enhanced? We develop a game-theoretic model to characterize the outcome of an architecture's deployment through the equilibrium of ISPs' decisions. This model enables us to: (1) analyze several key factors of the deployability of a new architecture such as the number of critical ISPs and the change of routing path; (2) explain the deploying outcomes of some previously proposed architectures/protocols such as IPv6, DiffServ, CDN, etc., and shed light on the "Internet flattening phenomenon"; (3) predict the deployability of a new architecture such as NDN, and compare its deployability with competing architectures. Our study suggests that the difficulty to deploy a new Internet architecture comes from the "coordination" of distributed ISPs. Finally, we design a mechanism to enhance the deployability of new architectures.
Network security devices intercept, analyze and act on the traffic moving through the network to enforce security policies. They can have adverse impact on the performance, functionality, and privacy provided by the network. To address this issue, we propose a new approach to network security based on the concept of short-term on-demand security exceptions. The basic idea is to bring network providers and (trusted) users together by (1) implementing coarse-grained security policies in the traditional way using conventional in-band security approaches, and (2) handling special cases policy exceptions in the control plane using user/application-supplied information. By divulging their intent to network providers, trusted users can receive better service. By allowing security exceptions, network providers can focus inspections on general (untrusted) traffic. We describe the design of an on-demand security exception mechanism and demonstrate its utility using a prototype implementation that enables high-speed big-data transfer across campus networks. Our experiments show that the security exception mechanism can improve the throughput of flows by trusted users significantly.
In this paper we consider an alternative possibility for routing money in the Internet ecosystem based on a spot market for interconnection service that operates alongside, or in addition to, the traditional contract service model. Recent work by others showed that under certain assumptions, enabling transit providers (i.e., networks that carry packets between networks) to sell their excess capacity on a best-effort basis improves both provider profit and consumer surplus. While prior work only focused on pricing strategies, we explore the technical feasibility of such a market in this paper. We consider what is needed to make such a spot market possible and focus on the interaction between technical and economic considerations. In particular, we describe two approaches that demonstrate how economic software defined exchanges (ESDXs) can be used as trusted intermediaries to tie the forwarding service to the flow of money.
A key concept of software-defined networking (SDN) is separation of the control and data plane. This idea provides several benefits, including fine-grained network control and monitoring, and the ability to deploy new services in a limited scope. Unfortunately, it is often cost-prohibitive for enterprises (and universities in particular) to upgrade their existing networks to wholly SDN-capable networks all at once. A compromise solution is to deploy SDN capabilities incrementally in the network. The challenge then is to take full advantage of SDN-based services throughout the network, in an integrated fashion rather than in a few "islands" of SDN support. At the University of Kentucky, SDN has been integrated into the campus network for several years. In this paper, we describe two aspects of this challenge, along with our solution approaches. One is the general reluctance of campus network administrations to allow novel or experimental (SDN-based) services in the production network. The other is how to extend such services throughout the legacy part of the network. For the former, we lay out a set of principles designed to ensure that the production service is not harmed. For the latter, we use policy based routing and a graph database to extend our previously-described VIP Lanes service. Our simulation results in a campus-like topology testbed show that we can provide a host with custom path service even if it is connected to a legacy router.
Current pricing mechanisms for end-to-end Internet transport involve heavyweight service-level agreements (SLAs) between providers, which are enforced through policy configurations in the Border Gateway Protocol. One drawback of this practice is that BGP gives preference to a single path, and thus inherently limits the richness of the network topology available to users at any time. Moreover, the coarse granularity and long time scales of interdomain SLAs limit the effect of competition and market forces. In this paper, we show how the use of software-defined infrastructure, in the form of an Economic Software-Defined Exchange Point (ESDX), can help enable a more dynamic interdomain ecosystem. In particular, providers can use the ESDX to establish short-term contracts and thus access a much richer set of path alternatives and contracts. We show that transparent pricing mechanisms are possible and that a pricing network equilibrium can be achieved.
This document was submitted to the IETF IPng area in response to RFC 1550 . Publication of this document does not imply acceptance by the IPng area of any ideas expressed within. Comments should be submitted to the big-internet@munnari.oz.au mailing list. 1. Executive Summary The two most commonly cited issues motivating the introduction of IPng are address depletion and routing table growth in IPv4. Further motivation is the fact that the Internet is witnessing an increasing diversity in the protocols and services found in the network. When evaluating alternatives for IPng, we should consider how well each alternative addresses the problems arising from this diversity. In this document, we identify several features that affect a protocol’s ability to operate in a multiprotocol environment and propose the incorporation of these features into IPng. Our thesis, succinctly stated, is: The next generation Internet Protocol should have features that support its use with a variety of protocol architectures.
Campus networks and enterprise networks increasingly depend on middleboxes (e.g., firewalls, NAT, load balancers, IDS/IDP) to provide essential services or enforce network policies. These middleboxes often limit the performance of network applications, especially those involved in big data transfer. To address this problem, we propose a Software Defined Networking (SDN) campus network architecture, called VIP Lanes, that provides the ability for pre-authorized, trusted users to create flows that bypass middleboxes, thereby enabling those users to achieve substantially better performance while maintaining security and policy compliance for other network traffic. In this paper, we present the VIP Lanes abstraction and describe an authorization and policy-enforcement service used to establish trusted VIP Lanes. We describe an initial prototype implementation that not only demonstrates the viability of the VIP Lanes approach, but also gives an indication of the types of performance improvements that are possible - in some cases approaching a two order of magnitude reduction in transmission times.
Internet Exchange Points (IXPs) play a major role in the current Internet architecture, serving as the connection point between Internet Service Providers (ISPs). Software-Defined Exchange Points (SDXs)-programmable versions of Internet Exchange Points (IXPs)-have been proposed as a way to give ISPs finer-grained control over the way packets are routed between ISPs. Leveraging software-defined networking (SDN) technology, an SDX enables control software to insert forwarding rules that route traffic on the granularity of individual flows. In this paper, we describe work-in-progress developing controllers for Software-Defined Internet Exchange Points that facilitate dynamic establishment of forwarding relationships between transit ISPs. The core hypothesis of our work is that the SDX can serve as a trusted intermediary, both facilitating establishment of dynamic peering agreements between ISPs, and enforcing their routing policies. Moreover, this building block, which we dub the Coin-Operated SDX, can be used to construct much more dynamic and fine-grained end-to-end routing services than are possible in today's infrastructure. In our model, each ISP independently but cooperatively defines the policies that the SDX enforces on its behalf. The SDX may also serve as a clearinghouse for the inter-ISP economic transactions that drive these policies, i.e., as Economic SDX (ESDX). We describe the overall architecture of a Coin-Op SDX, as well as the specific operations it must support to offer dynamic services. We believe that Coin-Op SDX can play a critical role in future software-defined inter-domain Internet infrastructure.
Homes now constitute a significant fraction of the Internet's “edge”. Despite a number of recent efforts, hard data about the structure and use of home networks is still hard to come by. In particular, data sets that include information about the traffic going into and out of homes tend to include very limited numbers of endpoints. Two of the main challenges in collecting such information are: (i) the computational and storage requirements of passive measurement systems, relative to the limited capabilities of home routers; and (ii) individuals' concerns about the privacy of their traffic data. In this paper we introduce HNFL, a lightweight, privacy-preserving passive measurement infrastructure for home networks. HNFL provides a lightweight network flow data collector in Linux kernel, which presents flow data in the form of bipartite graphs that support both latitudinal and longitudinal studies and a scalable and irreversible method to hide traffic identities from flow data while maintaining longitudinal comparison. We evaluate the correctness and efficiency of HNFL, and explore some applications for both networking researchers and home network users.
The Internet has been a key enabling technology for many new distributed applications and services. However, the deployment of new protocols and services in the Internet infrastructure itself has been sluggish, especially where economic incentives for network providers are unclear. In our work, we seek to develop an "economy plane" for the Internet that enables network providers to offer new network-based services (QoS, storage, etc.) for sale to customers. The explicit connection between economic relationships and network services across various time scales enables users to select among service alternatives. The resulting competition among network service providers will lead to overall better technological solutions and more competitive prices. In this paper, we present the architectural aspects of our ChoiceNet economy plane as well as some of the technological problems that need to be addressed in a practical deployment.
When playing online games, the user experience is often dictated by the performance of the network. To deliver the best possible gaming experience, game developers often find themselves developing work-arounds that try to mask the lack of control they have over of the existing TCP/IP Internet. ChoiceNet, an emerging future Internet architecture, attempts to give applications enhanced control (choice) over the service they receive from the network. In particular, ChoiceNet supports an economic plane in which applications can purchase services from any provider. Because providers are compensated, they are motivated to offer a variety of innovative, excellent services, enabling applications to select the service best suited for its needs. Instead of coding work-arounds, game developers can obtain precisely the network service that is needed to optimize the game experience. In this paper, we describe the emerging ChoiceNet architecture and show how computer games can benefit from the alternatives enabled by ChoiceNet. To demonstrate the benefits of the ChoiceNet architecture, we implemented a first person shooter game that uses ChoiceNet to “purchase” and then send data over the purchased path resulting in substantially lower latency than the default path. We describe the ChoiceNet services used to implement the game, and we present performance results that show a significant reduction in latency. We also show how ChoiceNet can be used to purchase reliable (non-lossy) communication paths that improve the user's experience.
Recent research has considered various architectural approaches in which route determination occurs separately from forwarding. Such offers many advantages, but also brings a number of challenges, not least of which is scalability. In this paper we consider the problem of computing domain-level end-to-end routes in the Internet. We describe a system architecture and a prototype route computation service that provides performance information along with paths. The results of our experiments, which involve updating billions of routes and serving thousands of requests per second, suggest that the resource requirements for a single-domain end-to-end path service (i.e., a service that provides paths from one access domain to all others) are fairly modest.
Software-Defined Networking (SDN) has been widely recognized as a promising way to deploy new services and protocols in future networks. The ability to "program" the network enables applications to create innovative new services inside the network itself. However, current SDN programmability comes with downsides that could hinder its adoption and deployment. First, in order to offer complete control, today's SDN networks provide low-level API's on which almost any type of service can be written. Because the starting point is a set of low-level API calls, implementing high-level complex services needed by future network applications becomes a challenging task. Second, the set of emerging SDN technologies that are beginning to appear have little in common with one another, making it difficult to set up a flow that traverses multiple SDN technologies/providers.In this paper we propose a new way to set up SDN networks spanning multiple SDN providers. The key to our approach is a Network Hypervisor service. The Network Hypervisor offers high-level abstractions and APIs that greatly simplify the task of creating complex SDN network services. Moreover, the Network Hypervisor is capable of internetworking various SDN providers together under a single interface/abstraction so that applications can establish end-to-end flows without the need to see, or deal with, the differences between SDN providers. (C) 2014 Elsevier B.V. All rights reserved.
Test beds such as GENI provide an ideal environment for experimenting with future internet architectures such as Choice Net. Unlike the narrow waist of the current Internet (IP), Choice Net encourages alternatives and competition at the network layer via an economic plane that allows users to choose and purchase precisely the services they need. In this paper we describe our experiences implementing the Choice Net architecture on GENI. Some features of GENI, such as the ability to program the network layer, to leverage existing protocols and software, to run real applications generating realistic traffic, and the ability to perform long-running experiments made GENI an ideal platform for Choice Net experimentation. However, we found that GENI currently lacks the tools needed to make it easy to use these features. To address this issue, we designed and implemented a GENI Experimenter Tool specifically designed and tailored to perform tasks commonly needed by experimenters such as dynamically configuring nodes, loading and compiling node-specific code, executing Click modules, running commands on sets of nodes, accessing the local file system on nodes, and dynamically logging into nodes.
Although the underlying network resources needed to support virtualized networks are rapidly becoming available, the tools and abstractions needed to effectively make use of these virtual networks is severely lacking. Although networks like GENI are now available to experimenters, creating an experimental network can still be a daunting and error-prone task. While virtual networks enable experimenters to build tailored networks from the "ground up", starting from scratch is rarely what an experimenter wants to do. Moreover, the challenges of incorporating real-world users into GENI experiments make it difficult to benefit real users or obtain realistic traffic. In this paper we describe a new service designed to simplify the process of setting up and running GENI experiments while at the same time adding support for real-world users to join GENI experiments. Our approach is based on a network hypervisor service used to deploy "HyperNets": pre-defined experimental environments that can be quickly and easily created by experimenters. To illustrate the utility and simplicity of our approach, we describe two example HyperNets, and show how our network hypervisor service is able to automatically deploy them on GENI. We then present some initial performance results from our implentation on GENI. Because our network hypervisor is itself a client of GENI (i.e., it calls the GENI AM APIs to create HyperNets), we briefly discuss our experience using GENI and the challenges we encountered mapping HyperNets onto the GENI framework.
Over the years, a number of source routing architectures have been put forward [2, 1, 5]. A source routing architecture is one where packets indicate the paths that they follow. Because such architectures seem to offer a number of advantages, especially with respect to competition and evolvability, we believe the case for a source-routed network layer is worth examining in detail. Our model of source routing consists of packets carrying (loose) provider-level source routes (i.e., interdomain paths) and distributed path providing servers that collect routing updates disseminated by transit providers, compute (inter-domain level) paths, and provide those paths to end systems for placement in packets. Thus routing is provided as a service with distributed path providers, similar to ROSE [6]. We also assume a mechanism along the lines of Platypus [7] so that providers can verify packets for routing-policycompliance and proof-of-payments. While it offers significant benefits, source routing also introduces some new technical and economic challenges. With such a different “factoring” of the routing process, we envision such an architecture to have a different business model in selling transit services to users. Because source routing empowers users to select indirect providers from whom users obtain transit service, users would be required to compensate their indirect providers in addition to the direct providers for the transit services. In order to scale the money transactions between users and all the direct and indirect transit providers, we envision a set of third party resellers, path brokers, who buy transit (relaying) service from providers, and then sell paths to users. Path brokers and path providers can be the same entity or can be separate. A major barrier towards deploying source routing is the “con-
To address shortcomings of the current Internet, many researchers are taking a clean-slate approach toward re-designing the Internet. These so-called clean-slate approaches discard the old assumptions, design principles, and constraints of the current Internet, set aside concerns about compatibility with existing software, and rebuild the entire network from scratch. Clean-slate approaches have the potential to produce a completely new Internet with new features and applications. However, clean-slate approaches are rarely backward compatible, thereby rendering existing legacy software and applications useless. Rewriting huge numbers of existing legacy applications to run in a clean-slate environment is simply not practical. This paper attempts to address this challenge of running legacy software on a clean-slate network architecture. We propose a general framework that supports a translation and policy interface by which users and administrators (or applications) can map legacy software onto emerging clean-slate networks. Using the framework, users are able to take advantage of the features of a clean-slate network while running existing applications. To check the correctness and completeness of our framework, we implemented an initial prototype and applied it in the context of our clean-slate Postmodern (PoMo) Internet Architecture. Using our system we show how existing applications can make use of, and benefit from, PoMo's multi-path routing capabilities.
J. Griffioen合作论文数University of Kentucky;Department of Computer Science 23
W. Brent Seales合作论文数Computer Science Department3