Orchestrating Heterogeneous Cyber-range Event Chains With Serverless-container Workflow
Yongquan Fu, Weihong Han, Dong Yuan · 2022
Cyber ranges need to run versatile network applications to increase the fidelity of the tests. With the growing complexity of cyberspace events that involve tens to hundreds of diverse applications and flexible execution orders of applications, it is increasingly challenging to orchestrate large-scale, complicated chains of heterogeneous Internet applications. State-of-the-art orchestration techniques do not scale out well due to the inefficient representation model and scheduling of network-centric and correlated Internet application activities. We present a serverless-container workflow orchestration scheme called Wukong. First, we overcome the heterogeneity of events with a workflow model that encodes event chains with compositional DAGs and unified serverless-container event triggers. Second, Wukong scales the scheduling of serverless-container workflows by automatically decomposing DAGs and push-pull coordinated event executions over distributed serverless-container runtime agents. Our evaluation on a real-world cyber range shows that Wukong is expressive, scalable and efficient for automatically emulating diverse event chains, in that the compositional modeling reduces the storage footprint over 57 to 58 times compared to baseline models, the response delay of Wukong is 1.52 to 2.74 times shorter than state-of-the-art orchestration engines, and the scheduling delay is 1.14 to 2.16 times smaller than those of the baseline approach.