FlowSpy: An Efficient Network Monitoring Framework Using P4 in Software-Defined Networks
Bowei Guan, Shan-Hsiang Shen · 2019
With the rapid development of network technology and growing services running, there is more network traffic on the Internet. To ensure the reliability and security of network, we need to do more effective network monitoring tasks that can help us gain more information for network troubleshooting and malicious traffic detection. Software-Defined Networks (or SDN, for short) provides a flexible platform for the network monitoring and relies on a central controller and switches interact with each other to gain a global view of traffic. However, the computation resources for network monitoring in switches are limited in SDN. Thus, too many monitoring tasks will affect data plane traffic performance. To address this issue, we propose FlowSpy, which is a load balancing network monitoring framework using P4 (Programming Protocol-Independent Packet Processors) programming language in SDN. P4 program can specify how a switch processes packets, that can reduce the overhead of the interaction between data plane and control plane in SDN, and provides more flexibility for monitoring than OpenFlow-based SDN. As compared to existing network monitoring methods, FlowSpy can take more monitoring capacity at each switch to complete more monitoring tasks without any overloaded nodes.