首页|面向内生安全交换机的段路由带内遥测方法

面向内生安全交换机的段路由带内遥测方法

扫码查看
近年来,网络技术的发展日新月异,基础设备及其所提供的网络服务也日益复杂.传统的网络管理和监控手段面临严峻的挑战.国内外研究人员提出段路由(Segment Routing,SR)和带内网络遥测(In-band Network Telemetry,INT)等技术来进行实时性更高、更细粒度的网络测量.然而,在流量迅速增长的网络环境下,带内网络遥测技术在实际使用中仍然存在着灵活部署、动态部署、高效部署等诸多难题.首先,传统INT技术缺乏合适的载体,数据包的开销随遥测路径长度线性增加,从而导致遥测监控的性能瓶颈问题.针对传统带内网络遥测系统比特开销大、难以高效部署的问题,提出了基于SRv6(Segment Rou-ting IPv6,SRv6)的带内网络遥测方法(SRv6_Based INT),通过研究减小INT和SR的开销,将两者无缝结合以实现轻量级的遥测.在本项工作中,通过设计INT的元数据,使其长度等于SRv6中的Segment字段,然后在每一跳中根据监控服务器下发的流表将SID修改成相应的INT元数据.该方法充分结合了两项技术的优点,并将开销控制在合理的范围,优于传统的带内网络遥测方法.
Segmental Routing in Band Telemetry Method for Endogenous Secure Switches
In recent years,network technology has evolved rapidly,and the infrastructure and network services provided have be-come increasingly complex.Traditional network management and monitoring tools are facing serious challenges.Domestic and in-ternational researchers have proposed segment routing(SR)and in-band network telemetry(INT)technologies to perform more real-time and fine-grained network measurements.However,in-band network telemetry technologies still have many challenges in practical use,such as flexible deployment,dynamic deployment,and efficient deployment in the rapidly growing network environ-ment.First,the traditional INT technology lacks a suitable carrier,and the packet overhead increases linearly with the telemetry path length,which leads to the performance bottleneck problem of telemetry monitoring.For the problem of high bit overhead and difficulties in efficient deployment of traditional in-band network telemetry systems,this paper proposes an SRv6_Based in-band network telemetry approach(SRv6_Based INT).In this work,the overhead of INT and SR is reduced and the two are seamlessly combined to achieve a lightweight and adaptive telemetry approach.In this work,the metadata of INT is designed so that its length is equal to the Segment field in SRv6,and then the corresponding SID is modified to the corresponding INT metadata in each hop according to the flow table issued by the monitoring server.This method fully combines the advantages of both tech-niques and keeps the overhead within a reasonable range,which is better than the traditional in-band network telemetry methods.

Segment routingIn-band network telemetrySoftware-defined network

顾周超、程光、赵玉宇

展开 >

东南大学网络空间安全学院 南京 211189

教育部计算机网络和信息集成重点实验室(东南大学)南京 211189

段路由 带内网络遥测 软件定义网络

国家重点研发计划山东计算机学会省重点实验室联合开放基金

2020YFB1804604SKLCN-2023-05

2024

计算机科学
重庆西南信息有限公司(原科技部西南信息中心)

计算机科学

CSTPCD北大核心
影响因子:0.944
ISSN:1002-137X
年,卷(期):2024.51(5)
  • 15