Intrusion detection and cybersecurity situational awareness technologies based on machine learning and deep learning have generally been limited by their reliance on prior knowledge and pre-training, which restricts their accuracy in detecting various types of attacks. The dynamic heterogeneous redundancy (DHR) construction technique, which detects attacks by evaluating the behavioral consistency of heterogeneous executers, offers a new perspective for intrusion detection. Based on this concept, a novel intrusion detection model called IDHES was proposed. This model was capable of detecting multiple types of intrusions without requiring pre-training. Additionally, synchronization of the target functions of heterogeneous executers was achieved through internal and external event conversions, thereby reducing the false positive rate caused by the heterogeneity of executers. Through theoretical analysis of the model, it was concluded that the detection accuracy of the IDHES model depends solely on the success rate of coordinated attacks by heterogeneous executers and the efficiency of target function synchronization. To verify the effectiveness of the model, a prototype MCU system based on the DHR architecture was constructed, and the target function synchronization method was implemented through internal and external event conversions. Finally, the attack detection capability of the model was tested using white-box instrumentation. The test results confirm the conclusion that the detection accuracy of the IDHES model depends solely on the success rate of coordinated attacks by heterogeneous executers and the efficiency of target function synchronization. Furthermore, the results demonstrate that IDHES can perform real-time detection of various types of attacks without relying on prior knowledge or pre-training.
Deterministic networks plan the entire network traffic and calculate the scheduling time to meet the critical traffic requirements of specific domains, enabling real-time and deterministic interaction of massive data. However, in dynamic industrial automation scenarios where devices undergo changes, existing mechanisms face challenges in quickly responding to dynamic transmission demand changes caused by rapid traffic migration. To address this issue, this paper proposes a reuse-based online scheduling mechanism that utilizes dynamic path planning of flows and coordinated scheduling of time slots to achieve deterministic transmission of dynamic flows. In the offline phase, the mechanism proposes a backbone link selection and a scalable intelligent routing strategy, constructs a set of routing and scheduling co-design constraints, and generates an offline scheduling table using an iterative scheduling algorithm. In the online scheduling phase, a reuse-based online scheduling algorithm is proposed to achieve rapid scheduling and deterministic transmission of dynamic real-time flows. It utilizes the offline scheduling results and the period offset of migrated flows. The reuse of offline scheduling results reduces computation time and expands the solution space. Experimental results demonstrate that the proposed mechanism achieves a maximum increase in scheduling success rate of 37.3% and reduces time costs by up to 66.6% compared to existing online scheduling algorithms.
The ever-growing carbon emission of information infrastructure accounts for a significant proportion of the global carbon emissions. Existing studies reduce carbon consumption mainly by improving power efficiency on specific facilities or energy source structures. However, these methods do not jointly consider the impact of computation and network resource distribution on carbon emission. In this paper, we propose a data-driven scheme named EcoNet using reinforcement learning to reduce carbon emissions by jointly scheduling computation and network resources. We dynamically monitor the status of the computation and network facilities using cloud-edge collaboration and software-defined networking. Based on the collected status information, we formulate the resource scheduling problem as an optimization problem, which comprehensively considers the carbon emission, electricity price, and quality of service. The problem has high computation complexity, and we solve the problem with the proposed EcoNet to achieve efficient scheduling and near-optimal performance based on the collected network status information. The evaluation results show that EcoNet can maintain good Quality of Service and save at least 17% of the overall cost considering the electricity bills and carbon emissions.
Deterministic Networking (DetNet) is a highly predictable and controllable network technology. It provides low packet loss rate and bounded latency data transmission for applications through resource reservation and scheduling mechanisms. However, DetNet is a hybrid traffic system, and the resource reservation mechanism cannot guarantee the deterministic requirements as the number of diverse deterministic applications increases. As a result, there is an urgent need for an efficient and fine-grained scheduling mechanism to meet the deterministic and bounded latency requirements. In this paper, we propose a novel end-to-end multi-policy deep reinforcement learning framework for automatically learning multiple policies and addressing the problem of multi-objective joint routing and scheduling. Specifically, we formulate the multi-action problem in joint routing and scheduling as a Multi-Markov Decision Process (MMDP) and design a new reward function to optimize multiple objectives. When optimizing the learning agent, we introduce an A3C-based multi-strategy optimization algorithm (A3C-MSO) to train two sub-policies, including the queue operation policy and the node operation policy for assigning queue operations to nodes. Furthermore, we integrate a graph convolutional network (GCN) into the learning framework to capture the spatial characteristics of irregular network topologies and enhance the algorithm's generalization ability. Extensive experimental results in different scenarios indicate that compared to the existing state-of-the-art mechanisms, the proposed mechanism has shown a 13% improvement in schedulability and an 18% enhancement in resource utilization. Particularly in high-load scenarios, the time cost of the proposed mechanism can be reduced by up to 40.5%. Furthermore, results obtained on real industrial network topology instances indicate that the proposed learning strategies exhibit good generalization and effectiveness in large-scale scheduling instances.
Virtual network function(VNF) capacity adjustment has become a research hotspot because it can significantly improve the resource utilization in the process of network service provision, but this technology will lead to an increase in network energy consumption when implemented. To solve this problem, a VNF capacity adjustment method for network energy saving is proposed. Firstly, a VNF capacity demand prediction method based on gated recurrent unit(GRU) and attention mechanism is proposed. Then, based on the predicted result of VNF capacity demand, a VNF capacity demand mapping method is designed, which utilizes deep reinforcement learning(DRL) to centrally deploy VNF instances and shut down idle nodes in the network to reduce energy consumption while improving network resource utilization. Experimental results show that, compared with existing VNF capacity adjustment methods, the proposed method improves resource utilization by at least 7.72% and reduces network energy consumption by at least 10.17%.
Software-Defined Networking (SDN) is the key technique of the next-generation network. Recently, SDN has become a hot spot in both academia and industry. Wide Area Network (WAN) is one of the primary application scenarios in the industry for SDN, which is known as Software-Defined WAN (SD-WAN). In SD - WAN, flexible traffic scheduling and network performance improvement are realized by the flow path programmability, which is enabled by the SDN controller to change dynamically the paths of flows traversing SDN switches. However, controller failure is a common phenomenon. When the controller fails, the switches controlled by the failed controller become offline, and the flows traversing the offline switches become offline too. In this way, the path programmability can not be guaranteed, and thus flexible flow control becomes invalid, leading to severe network performance degradation. This survey is presented to introduce the research works on maintaining path programmability in SD-WAN. First, the path programmability and the important feature for maintaining the path programmability in SD-WAN are introduced. Second, different types of existing solutions for coping with the controller failure in SD-WAN are proposed. Finally, potential improvements and future directions on this research topic are proposed.
The decoupling of the control plane and data plane in software-defined networking (SDN) not only encourages the innovation of network architecture but also leads to the update inconsistency problems on the data plane. Through the precious works, we realize that distributed data plane can cause the network reconfiguration conducted in an inconsistent manner which may lead to forwarding loops. To address this issue, we propose P4LoF, a loop-free solution for multi-flow updating in SDN. We constitute the minimal multi-flow update dependency graph by utilizing the greedy algorithm to decrease the complexity of scheduling consistent updates for multiple flows. In particular, we propose a novel forwarding model based on P4, one of the most popular and promising data plane programming languages, to resolve the deadlocks among update nodes in the dependency graph. The simulation results show that P4LoF significantly reduces the number of interactions between the controller and switches while preserving multi-flow update consistency. Moreover, P4LoF can reduce the flow table occupancy by at least 84% compared to the two-phase based update approach with up to 5% increase in bandwidth overhead.
Traditional routing schemes usually use fixed models for routing policies and thus are not good at handling complicated and dynamic traffic, leading to performance degradation (e.g., poor quality of service). Emerging Deep Reinforcement Learning (DRL) coupled with Software-Defined Networking (SDN) provides new opportunities to improve network performance with automatic traffic analysis and policy generation. However, existing DRL-based routing solutions usually rely on all node information to make routing decisions for the network and hence are both hard to converge in large networks and vulnerable to topology changes. In this paper, we propose ScaleDeep, a scalable DRL-based routing scheme for SDN, which improves the routing performance and is resilient to topology changes. Essentially, ScaleDeep takes advantage of partial control on network nodes and DRL. We select a set of critical nodes from a network as driver nodes, which can simulate the entire network operation, based on the control theory. By observing the traffic variation on the driver nodes, DRL dynamically adjusts some link weights for a weighted shortest path algorithm to change the routing paths and improve the routing performance. Limiting the control on driver nodes improves the convergence ability of DRL and reduces the dependency of the DRL agent on the fixed network topology. To validate the performance of ScaleDeep, we conduct packet-level simulations on different topologies. The results show that ScaleDeep outperforms existing DRL-based schemes by reducing the average flow completion time by up to 36% and exhibiting better robustness against minor topology changes.
针对SDN数据平面的软/硬件故障、错误配置等导致的控制平面和数据平面流规则不一致的问题,提出了基于P4的控制—数据平面流规则一致性校验机制(P4-based consistency verification mechanism for SDN control-data plane,P4CV)o P4CV首先向数据平面发送特定结构的探针,然后各P4交换机将数据平面实际流规则执行信息嵌入到探针,最后P4CV采用基于符号执行的一致性校验算法,完成对控制平面流规则配置和数据平面遥测信息的一致性校验.仿真结果表明,P4CV的单路径校验时长不受网络拓扑结构影响,仅与路径上交换节点数量线性相关.在同等网络规模和流规则配置的多路径转发场景中,P4CV在仅产生约0.06‰带宽开销的同时,比现有方案平均减少了约42%的校验时长.
Aiming at examining the problems of the low cache hit ratio and high-average routing hops in named data networking (NDN), this paper proposes a cache-optimization strategy based on dynamic popularity and replacement value. When the requested content arrives at the routing node, the latest popularity is calculated based on the number of requests in the current cycle and the popularity of the previous cycle. We adjust the node cache threshold according to the occupation of the node cache space and cache the content with a higher popularity than the threshold. When the cache is complete, the cache-optimization strategy considers the last request time, popularity, and transmission cost of cached content to calculate the replacement value of cached content. We move the content with the lowest replacement value out of the cache, and keep the content with a high replacement value. We deploy the proposed cache-optimization strategy by using a programmable language in a real network with programmable devices. The experimental results illustrate that the strategy proposed in this paper can effectively improve the cache hit ratio and reduce the average routing hops for user request responses compared with other traditional NDN caching strategies.
Named Data Networking (NDN) uses name to indicate content mechanism to divide content, and uses content names for routing and addressing. However, the traditional network devices that support the TCP/IP protocol stack and location-centric communication mechanisms cannot support functions such as in-network storage and multicast distribution of NDN effectively. The performance of NDN routers designed for specific functional platforms is limited, and it is difficult to deploy on a large scale, so the NDN network can only be implemented by software. With the development of data plane languages such as Programmable Protocol-Independent Packet Processors (P4), the practical deployment of NDN becomes achievable. To ensure efficient data distribution in the network, this paper proposes a protocol-independent multicast method according to each binary bit. The P4 language is used to define a bit vector in the data packet intrinsic metadata field, which is used to mark the requested port. When the requested content is returned, the routing node will check which port has requested the content according to the bit vector recorded in the register, and multicast the Data packet. The experimental results show that bitwise multicast technology can eliminate the number of flow tables distributed compared with the dynamic multicast group technology, and reduce the content response delay by 57% compared to unicast transmission technology.
Objectives:With the emergence and development of new network structures such as polymorphic network,the demand for network resource capacity is becoming more and more diverse.It is very difficult to adjust the distribution of virtual network functions (VNFs) carried on network slices for on-demand,dynamic and efficient resource capacity matching.This paper uses a data-driven VNF resource capacity prediction method to explore the pre-deployment of VNFs carried on network slices. Methods: Using the data-driven idea, a VNF resource capacity prediction method based on spatiotemporal feature extraction was adopted to pre-deploy VNFs for the upcoming slicing demand through resource capacity prediction. First, the time series of data stream used for prediction is subjected to two-stage weighting processing,and then the processed time series and its dependent spatial topology information are input into the network model for spatiotemporal feature extraction. For the extraction of spatial features, by given an adjacency matrix and a feature matrix,graph convolutional network is used to reorganize the spatial distribution features of time series in the Fourier domain. For the extraction of temporal features, the temporal dependencies of the input data are perceived through the information transfer between the units via gated recurrent units.Then,based on the mapping relationship between the data flow sequence and the number of VNF instances, the feedforward neural network performs data dimension transformation and finally outputs the VNF resource demand prediction results. Results: From the experimental results, the prediction performance of this method is mainly reflected in the following aspects:1.The prediction accuracy of this method is stable.The primary reason is that the method adopts a reasonable spatiotemporal feature extraction structure, which can effectively deal with both the spatial structure with non-Euclidean features and the time series features with contextual dependencies.The secondary reason is that the weighted preprocessing process of the input data stream sequence in this method effectively avoids the characteristic mutation caused by the burst flow in the network,and can truly reflect the changing trend of the data stream and slicing capacity requirements, thus obtaining stable prediction effect. 2. The method has the ability of spatiotemporal prediction. It shows that after a large amount of data training, the spatial feature extraction layer of the method can quickly calculate the topology relationship and data flow distribution of the network, and the temporal feature extraction layer can assist in predicting the sudden changes may occur in the data flow according to the potential correlation between data flows between nodes. The two feature extraction layers work in coordination to obtain accurate spatiotemporal prediction results.3.The method has the ability to convert data flow prediction results. It shows that this method can combine the mapping relationship between the fluctuation trend of data flow and the change trend of the number of VNF instances, and efficiently realizes the conversion of data flow prediction and network slice capacity prediction through the transformation of data dimension. Conclusions: With the vigorous development of artificial intelligence technology, polymorphic network has given computing, storage and transmission capabilities to virtual nodes on network slices,and has been able to realize the dual improvement of network resource utilization and user experience through the adaptive flow of business demand data on the basis of autonomously sensing data throughput and autonomously predicting the resource requirements of VNFs on nodes. With the help of machine learning algorithms, the VNF resource capacity demand prediction method VNFPre proposed for polymorphic network scenarios,it can judge the future VNF resource capacity demand of network slices, and provide a priori information for the placement and mapping of VNFs carried by network slices.
To address the problems of low cache hit ratio and high routing hops to obtain content in Named Data Networking (NDN), this paper proposes a Cache placement Policy based on Dynamic Popularity (DPCP). When the requested content arrives at the routing node, the latest popularity is calculated by combining the number of requests in current cycle and the popularity of the previous cycle, and the caching threshold is dynamically adjusted according to the occupancy of caching space, only content with popularity exceeding the current threshold is cached, thereby retaining the content with the highest probability of being requested in future time periods. This cache placement policy is also implemented using Programming Protocol-independent Packet Processors (P4) deployed on programmable data plane. Experimental results show that the proposed algorithm can effectively improve the cache hit ratio and reduce the average routing hops compared with the traditional caching policy.
The scale of modern information networks continues to expand, which puts forward higher requirements for inter-domain data communication on the Internet. Existing inter-domain routing protocols such as Border Gateway Protocol(BGP) cannot make intelligent routing decisions based on network performance, which easily leads to network congestion and reduces network transmission performance. This paper proposes a scalable inter-domain multi-link routing optimization mechanism based on multi-agent reinforcement learning. It can dynamically adjust the inter-domain routing strategy by sensing the network traffic distribution on multiple links between domains in real-time, thus maximizing the network traffic passing through each autonomous system and improving the overall throughput of the network. Experimental results show that, compared with the random algorithm and the SPF algorithm, the proposed algorithm can increase the network throughput by up to 26.1% and 16.4%, respectively, and achieves traffic balance on multiple links between domains.
Through the logically centralized control plane, software-defined network (SDN) provides giant convenience for the design of the network strategies, like load balancing, fault recovery, etc. However, when deploying those strategies on the data plane, transient link congestions may occur since the updating process among the distributed switches is asynchronous. To address this issue, we propose a congestion-aware mechanism for multi-flow updating in SDN. We first obtain the real-time traffic size of each flow to be updated through the link monitoring model. Then we use the congestion-aware algorithm to find the potential congested link and construct the dynamic dependency graph of the updating process, to generate the final updating sequence. Finally, the meter table is configured to limit the flow of crucial predecessor nodes that may have congestion deadlocks to mitigate the transient congestion.
As modern communication networks are growing more complicated and dynamic, designing a good Traffic Engineering (TE) policy becomes difficult due to the complexity of solving the optimal traffic scheduling problem. Deep Reinforcement Learning (DRL) provides us with a chance to design a model-free TE scheme through machine learning. However, existing DRL-based TE solutions cannot be applied to large networks. In this article, we propose to combine the control theory and DRL to design a TE scheme. Our proposed scheme ScaleDRL employs the idea from the pinning control theory to select a subset of links in the network and name them critical links. Based on the traffic distribution information, we use a DRL algorithm to dynamically adjust the link weights for the critical links. Through a weighted shortest path algorithm, the forwarding paths of the flows can be dynamically adjusted. The packet-level simulation shows that ScaleDRL reduces the average end-to-end transmission delay by up to 39% compared to the state-of-the-art in different network topologies.
When traditional machine learning methods are applied to network intrusion detection, they need to rely on expert knowledge to extract feature vectors in advance, which incurs lack of flexibility and versatility. Recently, deep learning methods have shown superior performance compared with traditional machine learning methods. Deep learning methods can learn the raw data directly, but they are faced with expensive computing cost. To solve this problem, a preprocessing method based on multipacket input unit and compression is proposed, which takes m data packets as the input unit to maximize the retention of information and greatly compresses the raw traffic to shorten the data learning and training time. In our proposed method, the CNN network structure is optimized and the weights of some convolution layers are assigned directly by using the Gabor filter. Experimental results on the benchmark data set show that compared with the existing models, the proposed method improves the detection accuracy by 2.49% and reduces the training time by 62.1%. In addition, the experiments show that the proposed compression method has obvious advantages in detection accuracy and computational efficiency compared with the existing compression methods.
Software-Defined Networking (SDN) provides flexible and global network management by decoupling control plane from data plane, and multiple controllers are deployed in the network in a logically centralized and physically distributed way. However, the existing approaches generally deploy the controllers with the same type in the network, which easily causes homogeneous controller common-mode fault. To this end, this paper proposes heterogeneous controller deployment in the SDN, considering the different types of controllers and relevant criteria (e.g., delay, control link interruption rate, and controller fault rate). Then, we introduce a Safe and Reliable Heterogeneous Controller Deployment (SRHCD) approach, consisting of two stages. Stage 1 determines the type and the number of heterogeneous controllers required for the SDN network based on the dynamic programming. Stage 2 divides the SDN network into multiple subnets by k-means algorithm and improves the genetic algorithm to optimize the heterogeneous controller deployment in these SDN subnets to ensure reliable switch-controller communications. Finally, the simulation results show that the proposed approach can effectively reduce the control plane fault rate and increase the attack difficulties. Besides, the switch-controller delay has been lowered by 16.5% averagely.
Segment Routing (SR) is a new routing paradigm based on source routing and provide traffic engineering (TE) capabilities in IP network. By extending interior gateway protocol(IGP), SR can be easily applied to IP network. However, upgrading current IP network to a full SR one can be costly and difficult. Hybrid IP/SR network will last for some time. Aiming at the low flexibility problem of static TE policies in the current SR networks, this paper proposes a Deep Reinforcement Learning (DRL) based TE scheme. The proposed scheme employs multi-path transmission and use DRL to dynamically adjust the traffic splitting ratio among different paths based on the network traffic distribution. As a result, the network congestion can be mitigated and the performance of the network is improved. Simulation results show that our proposed scheme can improve the throughput of the network by up to 9% than existing schemes.
IEEE 802.11ah, marketed as Wi-Fi HaLow, is a new sub-1GHz Wi-Fi technology for the Internet of Things (IoT), aiming to address the major challenge of the IoT: providing connectivity among a large number of power-constrained stations deployed over a wide area. In order to achieve this goal, several novel features are introduced in IEEE 802.11ah in both the Physical Layer (PHY) and Media Access Control (MAC) layer. These features have been extensively studied from various perspectives in the past years. To provide readers with an insight into these novel features, this article provides an overview of the IEEE 802.11ah technology and conducts a comprehensive summary and analysis on the related research, revealing how to utilize these novel features to satisfy the demanding IoT performance criteria. Furthermore, the remaining issues that need to be addressed to fully realize the vision of large-scale and low power Wi-Fi networks for the IoT are discussed.