An Effective Policy Relocation Scheme for VM Migration in Software-Defined Networks

Kun Xu,Chuang Lin,Zhen Chen,Kun Meng,Mourad Hakmaoui
DOI: https://doi.org/10.1109/ICCCN.2015.7288376
2015-01-01
Abstract:To achieve the flexibility in resource optimization, fault tolerance and load balancing, virtual machines(VMs) should be effectively migrated in data center networks(DCN). VMs are regulated by security policies and also required to relocate the policy during VM migration, which is a challenge problem to maintain not only the isolation among different domains and tenants, but also the consistency of policy configuration. In this paper, we consider the problem of policy relocation in Software-defined Network(SDN) context since it provides flexible control. We introduce a formal model describing the problem and present a novel policy relocation scheme called VPRS(a Virtual Policy Relocation Scheme), which is based on policy-aware principle and space-optimized method. It can prevent fragmentation of policy and reduce the memory usage while accurately relocating influenced policies. On the other hand, it also simplifies the management of policy. Specifically, VPRS contains novel algorithms for policy relocation, an app-layer policy management, policy translator and component for controllers notification. We define three actions of policy relocation based on the policy abstraction, and then describe the advantage of our scheme about selecting an optimized network address as target address. Then we introduce the core space-optimized algorithms, and evaluate the effectiveness of our scheme by providing consumption on their running overhead and utilization of rule space. Our scheme performs well on real policy sets, and has dramatic reduction by even up to 90\% on rule space costs with high utilization.
What problem does this paper attempt to address?