The Experts below are selected from a list of 3132 Experts worldwide ranked by ideXlab platform
Laizhong Cui - One of the best experts on this subject based on the ideXlab platform.
-
learning based network path planning for traffic engineering
Future Generation Computer Systems, 2019Co-Authors: Yuan Zuo, Geyong Min, Laizhong CuiAbstract:Abstract Recent advances in traffic engineering offer a series of techniques to address the network problems due to the explosive growth of Internet traffic. In traffic engineering, dynamic path planning is essential for prevalent Applications, e.g., load balancing, traffic monitoring and Firewall. Application-specific methods can indeed improve the network performance but can hardly be extended to general scenarios. Meanwhile, massive data generated in the current Internet has not been fully exploited, which may convey much valuable knowledge and information to facilitate traffic engineering. In this paper, we propose a learning-based network path planning method under forwarding constraints for finer-grained and effective traffic engineering. We form the path planning problem as the problem of inferring a sequence of nodes in a network path and adapt a sequence-to-sequence model to learn implicit forwarding paths based on empirical network traffic data. To boost the model performance, attention mechanism and beam search are adapted to capture the essential sequential features of the nodes in a path and guarantee the path connectivity. To validate the effectiveness of the derived model, we implement it in Mininet emulator environment and leverage the traffic data generated by both a real-world GEANT network topology and a grid network topology to train and evaluate the model. Experiment results exhibit a high testing accuracy and imply the superiority of our proposal.
Yuan Zuo - One of the best experts on this subject based on the ideXlab platform.
-
learning based network path planning for traffic engineering
Future Generation Computer Systems, 2019Co-Authors: Yuan Zuo, Geyong Min, Laizhong CuiAbstract:Abstract Recent advances in traffic engineering offer a series of techniques to address the network problems due to the explosive growth of Internet traffic. In traffic engineering, dynamic path planning is essential for prevalent Applications, e.g., load balancing, traffic monitoring and Firewall. Application-specific methods can indeed improve the network performance but can hardly be extended to general scenarios. Meanwhile, massive data generated in the current Internet has not been fully exploited, which may convey much valuable knowledge and information to facilitate traffic engineering. In this paper, we propose a learning-based network path planning method under forwarding constraints for finer-grained and effective traffic engineering. We form the path planning problem as the problem of inferring a sequence of nodes in a network path and adapt a sequence-to-sequence model to learn implicit forwarding paths based on empirical network traffic data. To boost the model performance, attention mechanism and beam search are adapted to capture the essential sequential features of the nodes in a path and guarantee the path connectivity. To validate the effectiveness of the derived model, we implement it in Mininet emulator environment and leverage the traffic data generated by both a real-world GEANT network topology and a grid network topology to train and evaluate the model. Experiment results exhibit a high testing accuracy and imply the superiority of our proposal.
Karamjeet Kaur - One of the best experts on this subject based on the ideXlab platform.
-
Software Defined Networking based Routing Firewall
International Conference on Computational Techniques in Information and Communication Technologies (ICCTICT), 2016Co-Authors: Karamjeet Kaur, Sukhveer Kaur, Vipin GuptaAbstract:-A router's main function is to allow communication between different networks as quickly as possible and in efficient manner. The communication can be between LAN or between LAN and WAN. A Firewall's function is to restrict unwanted traffic. In big networks, routers and Firewall tasks are performed by different network devices. But in small networks, we want both functions on same device i.e. one single device performing both routing and Firewalling. We call these devices as routing Firewall. In Traditional networks, the devices are already available. But the next generation networks will be powered by Software Defined Networks. For wide adoption of SDN, we need northbound SDN Applications such as routers, load balancers, Firewalls, proxy servers, Deep packet inspection devices, routing Firewalls running on OpenFlow based physical and virtual switches. But the SDN is still in early stage, so still there is very less availability of these Applications. There already exist simple L3 Learning Application which provides very elementary router function and also simple stateful Firewalls providing basic access control. In this paper, we are implementing one SDN Routing Firewall Application which will perform both the routing and Firewall function.
-
Building stateful Firewall over software defined networking
Advances in Intelligent Systems and Computing, 2016Co-Authors: Karamjeet Kaur, Japinder SinghAbstract:Current network architectures are ill suited to meet today’s enterprise and academic requirements. Software Defined Networking (SDN) is a new way to Design, Build and Operate Networks. It replaces static, inflexible and complex networks with networks that are agile, scalable and innovative. The main idea is to decouple the control and data planes, allowing the network to be programmatically controlled. A key element of SDN architectures is the controller. This logically centralized entity acts as a network operating system, providing Applications with a uniform and centralized programming interface to the underlying network. But it also introduces new security challenges. The challenge of building robust Firewalls is the main challenge for protection of OpenFlow networks. The main problem with traditional Firewall is that Network Administrator cannot modify/extend the capabilities of traditional vendor-specific Firewall. Network Administrator can only configure the Firewall according to the specifications given by the Firewall vendor. To solve these problems we developed stateful Firewall Application that runs over SDN controller to show that most of the Firewall functionalities can be built on software, without the aid of a dedicated hardware.
-
Programmable Firewall Using Software Defined Networking
IEEE INDIACom, 2015Co-Authors: Karamjeet Kaur, Japinder Singh, Krishan Kumar, Navtej Singh GhummanAbstract:Software Defined Networking is an exciting technology that enables innovation and flexibility in designing and managing networks, but it also introduces new security issues. Our Major challenge is to build powerful and flexible Firewall Applications for protecting software defined based networks. In this paper we focus on designing and developing OpenFlow based Firewall Application. The implementation shows that most of the Firewall functionalities can be built using software, without need of dedicated hardware. We are using open source POX Controller based on python for our experiments. To perform experiment, we have used VMPlayer virtualization solution and installed Mininet emulator for creating network topologies. In this paper, we present the implementation details as well as experimentation results of Firewall Application.
Geyong Min - One of the best experts on this subject based on the ideXlab platform.
-
learning based network path planning for traffic engineering
Future Generation Computer Systems, 2019Co-Authors: Yuan Zuo, Geyong Min, Laizhong CuiAbstract:Abstract Recent advances in traffic engineering offer a series of techniques to address the network problems due to the explosive growth of Internet traffic. In traffic engineering, dynamic path planning is essential for prevalent Applications, e.g., load balancing, traffic monitoring and Firewall. Application-specific methods can indeed improve the network performance but can hardly be extended to general scenarios. Meanwhile, massive data generated in the current Internet has not been fully exploited, which may convey much valuable knowledge and information to facilitate traffic engineering. In this paper, we propose a learning-based network path planning method under forwarding constraints for finer-grained and effective traffic engineering. We form the path planning problem as the problem of inferring a sequence of nodes in a network path and adapt a sequence-to-sequence model to learn implicit forwarding paths based on empirical network traffic data. To boost the model performance, attention mechanism and beam search are adapted to capture the essential sequential features of the nodes in a path and guarantee the path connectivity. To validate the effectiveness of the derived model, we implement it in Mininet emulator environment and leverage the traffic data generated by both a real-world GEANT network topology and a grid network topology to train and evaluate the model. Experiment results exhibit a high testing accuracy and imply the superiority of our proposal.
Alm M. Afshar - One of the best experts on this subject based on the ideXlab platform.
-
Implementation of Portion Approach in Distributed Firewall Application for Network Security Framework
2012Co-Authors: Kaur Harleen, E., Omid Mahdiebadati, Alm M. AfsharAbstract:The stimulate of this research seeks collaboration of Firewalls which, could reach to the capability of distributed points of security policy; the front-end entity may much interact by the invaders so the separation between this entity and back-end entity to make the secure domain protection is necessary; collaborative security entity has the various task in the organization and there is a certain security policy to apply in; the entities like DPFF have to be protected from outsiders. Firewalls are utilized typically to be the main layer of security in the network framework. The research is presented the particular segment of the proposed framework that DPFF based on the developed iptable Firewall to be the layers of defense, which is protected front and backend of the framework with a dynamic security and policy update to control the framework's safeguard through proposed portion approach algorithm that utilize to reduce the traffic and efficiency in detection and policy update mechanism. The policy update mechanism for DPFF is given the way of its employment. The complete framework signifies a distributed Firewall, where the administrator configures the policy rules set, which could be separately or else from administration nodes' side.Comment: 11 pages, 8 figurs, 4 tables, IJCSI; ISSN (Online): 1694-081