arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.35585cs.NI

资源与响应性:大规模移动目标防御控制平面下SDN控制器运行时基准测试

Resource versus Responsiveness: Benchmarking SDN Controller Runtimes for a Moving-Target-Defense Control Plane at Scale

Souhail Chakkour, Umesh Biswas, Charan Gudla

首次发表 更新
浏览论文内容

中文总结 AI 辅助

该研究针对SDN基移动目标防御系统中控制器运行时特性被忽视的问题,将CPAM逻辑移植到三款主流控制器并在500主机规模下测试,揭示了不同控制器在资源消耗与响应性上的权衡,明确控制器选择是MTD系统的核心设计决策。

中文摘要 AI 辅助

基于软件定义网络(SDN)构建的网络移动目标防御(MTD,Moving Target Defense)会持续轮换面向主机的地址,以破坏攻击者的侦察效果。每次轮换都会引发控制平面的突变流量,而新连接可能同时需要响应式流规则安装。然而在MTD相关研究中,SDN控制器的运行时特性通常被视为实现细节。我们的研究表明,该特性会对性能产生实质性影响。我们将相同的连续性保持地址突变(CPAM,Continuity-Preserving Address Mutation)逻辑移植到三款广泛使用的控制器:Ryu(单线程协作式Python实现)、OpenDaylight和ONOS(后两者均为多线程JVM实现),并采用符合RFC 8456标准的方法,在包含500台主机的相同校园网络架构下对每款控制器进行10次测试评估。三款控制器均能实现接近零的丢包率、亚毫秒级抖动,并保持已建立的会话不中断,但它们的控制平面行为差异显著。OpenDaylight和ONOS的响应式延迟低且稳定,而Ryu将响应式流安装排在周期性轮换工作之后串行执行,导致响应式往返时间(RTT)升高约100倍,并引发少量连接建立失败。Ryu的内存使用量极低,ONOS则达到了与OpenDaylight相当的响应式延迟水平,同时在三者中CPU利用率最低,活动堆内存也小于OpenDaylight。这些结果揭示了资源消耗与响应性之间不同的权衡点,表明在基于SDN的MTD系统中,控制器选择应被视为一等设计决策。

英文摘要

Network Moving Target Defense (MTD) built on Software-Defined Networking (SDN) continuously rotates host-facing addresses to invalidate an attacker's reconnaissance. Each rotation creates a burst of control-plane mutations, while new connections may simultaneously require reactive flow installation. Yet SDN controller runtime is usually treated as an implementation detail in the MTD literature. We show that it materially affects performance. We port the same Continuity-Preserving Address Mutation (CPAM) logic to three widely used controllers: Ryu (single-threaded cooperative Python), OpenDaylight, and ONOS (both multi-threaded JVM), and evaluate them on an identical 500-host campus fabric using an RFC 8456-aligned methodology with ten runs per controller. All three provide near-zero loss, sub-millisecond jitter, and preserve established sessions, but their control-plane behavior differs sharply. OpenDaylight and ONOS keep reactive latency low and stable, whereas Ryu serializes reactive flow installation behind periodic rotation work, increasing reactive RTT by about 100x and causing a small number of setup-time failures. Ryu uses far less memory, while ONOS achieves OpenDaylight-class reactive latency with the lowest CPU utilization of the three and a smaller live heap than OpenDaylight. These results expose distinct resource-versus-responsiveness operating points and show that controller selection should be treated as a first-class design decision in SDN-based MTD.

发表机构

  • Mississippi State University(密西西比州立大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑