Searcharxiv⌕ Search

arXiv subjects

Ashraf Matrawy

Publications and source records attributed to Ashraf Matrawy.

43 records · Page 3Linked to original sources

Towards Secure Slicing: Using Slice Isolation to Mitigate DDoS Attacks on 5G Core Network Slices

In this paper, we propose a solution to proactively mitigate Distributed Denial-of-Service attacks in 5G core network slicing using slice isolation. Network slicing is one of the key technologies that allow 5G networks to offer dedicated resources to different industries (services). However, a Distributed Denial-of-Service attack could severely impact the performance and availability of the slices as they could share the same physical resources in a multi-tenant virtualized networking infrastructure. Slice isolation is an essential requirement for 5G network slicing. In this paper, we use network isolation to tackle the challenging problem of Distributed Denial-of-Service attacks in 5G network slicing. We propose the use of a mathematical model that can provide on-demand slice isolation as well as guarantee end-to-end delay for 5G core network slices. We evaluate the proposed work with a mix of simulation and experimental work. Our results show that the proposed isolation could mitigate Distributed Denial-of-Service attacks as well as increase the availability of the slices. We believe this work will encourage further research in securing 5G network slicing.

cs.NI↗

Optimal Slice Allocation in 5G Core Networks

5G network slicing is essential to providing flexible, scalable and on-demand solutions for the vast array of applications in 5G networks. Two key challenges of 5G network slicing are function isolation (intra-slice) and guaranteeing end-to-end delay for a slice. In this paper, we address the question of optimal allocation of a slice in 5G core networks by tackling these two challenges. We adopt and extend the work by D. Dietrich [1] to create a model that satisfies constraints on end-to-end delay as well as isolation between components of a slice for reliability.

cs.NI↗

Modeling and Analysis of SDN Control Applications using Vector Spaces

Unlike traditional networks which are statically configured, SDN control applications are dynamic and are becoming more heterogeneous and complex. There is a great need for a framework to reason about the behavior of the various SDN applications. To the best of our knowledge, current network modeling frameworks were not designed to incorporate the application logic into their models, and thus can not be used to accurately model the application. In this paper, we suggest the possibility of leveraging the impact which control applications assert on the network information base to reason about the behavior of such applications. Based on that, we propose SDN-VSA, a framework that models SDN control applications as a set of affine transformations in some vector space. Finally, we present an analytical formulation for such framework, and discuss a use-case. For simplicity, we only consider the case of OpenFlow version 1.0.

cs.NI↗

Could Network View Inconsistency Affect Virtualized Network Security Functions?

With SDN increasingly becoming an enabling technology for NFV in the cloud, many virtualized network functions need to monitor the network state in order to function properly. An outdated network view at the controllers can impact the performance of those virtualized network functions. In earlier work, we identified two main factors contributing to an outdated network view in the case of a load-balancer: network state collection and controllers' state distribution. In this paper, we anticipate that the impact might be different in case of security functions. Therefore, we study the impact of an outdated network view on an anomaly-based IDS application. In particular, we investigate: (1) the impact of controllers' state distribution on the performance of a distributed IDS in the case of a DDoS attack; and (2) the impact of network state collection on the performance of an IDS in the case of a TCP SYN flood attack. Our results showed that the outdated network view had negative impact on the IDS anomaly-detection performance in the experiments that we conducted.

cs.NI↗

An Empirical Model of Packet Processing Delay of the Open vSwitch

Network virtualization offers flexibility by decoupling virtual network from the underlying physical network. Software-Defined Network (SDN) could utilize the virtual network. For example, in Software-Defined Networks, the entire network can be run on commodity hardware and operating systems that use virtual elements. However, this could present new challenges of data plane performance. In this paper, we present an empirical model of the packet processing delay of a widely used OpenFlow virtual switch, the Open vSwitch. In the empirical model, we analyze the effect of varying Random Access Memory (RAM) and network parameters on the performance of the Open vSwitch. Our empirical model captures the non-network processing delays, which could be used in enhancing the network modeling and simulation.

cs.NI↗

A Clustering-based Consistency Adaptation Strategy for Distributed SDN Controllers

Distributed controllers are oftentimes used in large-scale SDN deployments where they run a myriad of network applications simultaneously. Such applications could have different consistency and availability preferences. These controllers need to communicate via east/west interfaces in order to synchronize their state information. The consistency and the availability of the distributed state information are governed by an underlying consistency model. Earlier, we suggested the use of adaptively-consistent controllers that can autonomously tune their consistency parameters in order to meet the performance requirements of a certain application. In this paper, we examine the feasibility of employing adaptive controllers that are built on-top of tunable consistency models similar to that of Apache Cassandra. We present an adaptation strategy that uses clustering techniques (sequential k-means and incremental k-means) in order to map a given application performance indicator into a feasible consistency level that can be used with the underlying tunable consistency model. In the cases that we modeled and tested, our results show that in the case of sequential k-means, with a reasonable number of clusters (>= 50), a plausible mapping (low RMSE) could be estimated between the application performance indicators and the consistency level indicator. In the case of incremental k-means, the results also showed that a plausible mapping (low RMSE) could be estimated using a similar number of clusters (>= 50) by using a small threshold (~$ 0.01).

cs.NI↗

Maintaining an Up-to-date Global Network View in SDN

Maintaining an up-to-date global network view is of crucial importance for intelligent SDN applications that need to act autonomously. In this paper, we focus on two key factors that can affect the controllers' global network view and subsequently impact the application performance. Particularly we examine: (1) network state collection, and (2) network state distribution. First, we compare the impact of active and passive OpenFlow network state collection methods on an SDN load-balancing application running at the controller using key performance indicators that we define. We do this comparison through: (i) a simulation of a mathematical model we derive for the SDN load-balancer, and (ii) an evaluation of a load-balancing application running on top of single and distributed controllers. Further, we investigate the impact of network state collection on a state-distribution-aware load-balancing application. Finally, we study the impact of network scale on applications requiring an up-to-date global network view in the presence of the aforementioned key factors. Our results show that both the network state collection and network state distribution can have an impact on the SDN application performance. The more the information at the controllers becomes outdated, the higher the impact would be. Even with those applications that were designed to mitigate the issues of controller state distribution, their performance was affected by the network state collection. Lastly, the results suggest that the impact of network state collection on application performance becomes more apparent as the number of distributed controllers increases.

cs.NI↗