Kabir, Kantola, and Llorente Santos
214
The setup comprises of two networks served by their respective CES nodes. Each
network has an open flow switch at its edge, which processes the traffic passing it as per
the controller generated rules. The edge of the network has two links/interfaces to send
and receive the traffic from: (a) legacy Internet, simulated with the public IPv4 addresses;
and (b) networks connected via private transit links. The setup allows testing both
modes of CES technology: (a) CETP‐based policy communication, for establishing com‑
munication between hosts in different CES networks; and (b) RGW for interoperability
of CES with legacy IP networks.
We define the following KPIs for CES security testing:
● Session setup delay: is the average CETP session setup time when using the CES
prototype, including the delay due to control/data plane split architecture;
● Signalling round trips: for creating new outbound and inbound CETP sessions;
● Cost of Security: is the processing delay introduced to the session setup time;
● False Negatives: is percentage of hacker flows wrongly admitted into the network;
● False Positives: is percentage of ordinary users classified as attacker;
● Contribution of security: compared to CES without the security mechanisms.
9.4.1 Evaluating the CETP Policy‐based Communication
As discussed above, the CETP signalling can be split into:
1) DNS NAPTR query and response for identifying the locator of the remote CES
node;
2) CETP policy negotiation, which upon success, allows tunnelling of the subsequent
data packets between hosts on the negotiated data RLOCs, across the networks.
We tested and analyzed the connection setup delay for over a hundred new CETP
flows between CES nodes. The delay perceived by the originating host is measured as
the time to resolve a DNS query for a destination domain, as well as the time to forward
OVS-B
DNS
OVS-A
CES-A Network
192.168.0.0/24
CES-B Network
192.168.0.0/24
Internet
198.18.0.0/24
fc00:bbbb::/64
ISP Transit Link
172.16.0.0/24
fc00:cccc::/64
HTTP(s)
DNS/DHCP
HTTP(s)
DNS/DHCP
Figure 9.6 Implementation of CES testbed.
214
The setup comprises of two networks served by their respective CES nodes. Each
network has an open flow switch at its edge, which processes the traffic passing it as per
the controller generated rules. The edge of the network has two links/interfaces to send
and receive the traffic from: (a) legacy Internet, simulated with the public IPv4 addresses;
and (b) networks connected via private transit links. The setup allows testing both
modes of CES technology: (a) CETP‐based policy communication, for establishing com‑
munication between hosts in different CES networks; and (b) RGW for interoperability
of CES with legacy IP networks.
We define the following KPIs for CES security testing:
● Session setup delay: is the average CETP session setup time when using the CES
prototype, including the delay due to control/data plane split architecture;
● Signalling round trips: for creating new outbound and inbound CETP sessions;
● Cost of Security: is the processing delay introduced to the session setup time;
● False Negatives: is percentage of hacker flows wrongly admitted into the network;
● False Positives: is percentage of ordinary users classified as attacker;
● Contribution of security: compared to CES without the security mechanisms.
9.4.1 Evaluating the CETP Policy‐based Communication
As discussed above, the CETP signalling can be split into:
1) DNS NAPTR query and response for identifying the locator of the remote CES
node;
2) CETP policy negotiation, which upon success, allows tunnelling of the subsequent
data packets between hosts on the negotiated data RLOCs, across the networks.
We tested and analyzed the connection setup delay for over a hundred new CETP
flows between CES nodes. The delay perceived by the originating host is measured as
the time to resolve a DNS query for a destination domain, as well as the time to forward
OVS-B
DNS
OVS-A
CES-A Network
192.168.0.0/24
CES-B Network
192.168.0.0/24
Internet
198.18.0.0/24
fc00:bbbb::/64
ISP Transit Link
172.16.0.0/24
fc00:cccc::/64
HTTP(s)
DNS/DHCP
HTTP(s)
DNS/DHCP
Figure 9.6 Implementation of CES testbed.
