Acila: Attaching Identities of Workloads for Efficient Packet Classification in a Cloud Data Center Network

09/17/2021
by   Kentaro Ohnishi, et al.
0

IP addresses and port numbers (network based identifiers hereafter) in packets are two major identifiers for network devices to identify systems and roles of hosts sending and receiving packets for access control lists, priority control, etc. However, in modern system design on cloud, such as microservices architecture, network based identifiers are inefficient for network devices to identify systems and roles of hosts. This is because, due to autoscaling and automatic deployment of new software, many VMs and containers consisting of the system (workload hereafter) are frequently created and deleted on servers whose resources are available, and network based identifiers are assigned based on servers where containers and VMs are running. In this paper, we propose a new system, Acila, to classify packets based on the identity of a workload at network devices, by marking packets with the necessary information extracted from the identity that usually stored in orchestrators or controllers. We then implement Acila and show that packet filtering and priority control can be implemented with Acila, and entries for them with Acila is more efficient than conventional network based identifiers approach, with little overhead on performance

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/18/2019

IoT Device Fingerprint using Deep Learning

Device Fingerprinting (DFP) is the identification of a device without us...
research
01/03/2022

A Priority-Aware Multiqueue NIC Design

Low-level embedded systems are used to control cyber-phyiscal systems in...
research
07/05/2022

Many-fields Packet Classification Using R-Tree and Field Concatenation Technique

Software-defined Networking is an approach that decouples the software-b...
research
07/07/2020

PINT: Probabilistic In-band Network Telemetry

Commodity network devices support adding in-band telemetry measurements ...
research
05/03/2023

Towards a Real-Time IoT: Approaches for Incoming Packet Processing in Cyber-Physical Systems

Embedded real-time devices for monitoring, controlling, and collaboratio...
research
12/27/2018

CASPR: Judiciously Using the Cloud for Wide-Area Packet Recovery

We revisit a classic networking problem -- how to recover from lost pack...
research
09/27/2021

Towards "Zero-buffer" Datacenter Networks

In this paper, we investigate the possibility of building a data center ...

Please sign up or login with your details

Forgot password? Click here to reset