Policy Routing Using Process-Level Identifiers

2016 IEEE International Conference on Cloud Engineering Workshop (IC2EW)(2016)

引用 4|浏览29
暂无评分
摘要
Enforcing and routing based on network-wide policies remains a crucial challenge in the operation of large-scale enterprise and datacenter networks. As current dataplane devices solely rely on layer 2 - layer 4 identifiers to make forwarding decisions, there is no notion of the exact origin of a packet in terms of the sending user or process. In this paper we ask the question: Can we go beyond the MAC? That is, can fine-grained process-level information like user ids, process ids or a cryptographic hash of the sending executable be semantically used to make forwarding decisions within the network? Toward this goal, we present a system enabling such capabilities without the need for modification in applications or the operating system's networking stack. We implemented an early prototype leveraging the P4 technology for protocol-independent packet processing and forwarding in conjunction with on-board tools of the Linux operating system. We finally evaluate our system with regards to practicability and discuss the performance-behavior of our implementation.
更多
查看译文
关键词
process-level identifiers,large-scale enterprise,datacenter networks,process-level information,cryptographic hash,user id,process id,Linux operating system,P4 technology,protocol-independent packet processing,on-board tools,software-defined networking
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要