Traffic-Aware Rule-Cache Assignment in SDN: Security Implications

Sudip Misra, Niloy Saha, Rupayan Bhakta · 2020

Cache-based flow-rule management in SDN aims to address the issue of limited ternary content addressable memory (TCAM) in switches by combining software switches (cache) with TCAM hardware. This preserves the fast packet-processing capabilities of hardware, while providing a large flow-space for rules pertaining to QoS management and security. However, to improve the reliability of such software caches, and meet requirements such as scalability and fault-tolerance, they should be placed in a distributed manner in the network. The dynamic assignment of these software caches with the hardware switches is challenging; static or improper assignment may lead to increased load imbalance, which affects overall network performance, and may make the network more vulnerable to attacks such as denial-of-service. Therefore, in this paper, we consider the traffic-aware rule cache assignment problem with an aim to lower the overall delay and network overhead. We model the problem using a many-to-many matching framework, and show that the proposed algorithm arrives at a pairwise stable outcome. Extensive simulation results show that the proposed scheme reduces the average delay by 10% and 35%, and the total network overhead by 19% and 39% compared to minimumdistance based and random based cache assignment schemes, respectively.

Read the paper · More papers on PaperTik