<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Time Dependent Di usion Model for Security Driven Software De ned Networks</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Tadeusz Czachorski</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          ,
          <addr-line>Erol Gelenbe</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Institute of Theoretical and Applied Informatics Polish Academy of Sciences ul. Baltycka 5</institution>
          ,
          <addr-line>44-100 Gliwice</addr-line>
          ,
          <country country="PL">Poland</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>The Silesian University of Technology Akademicka 16</institution>
          ,
          <addr-line>44-100 Gliwice</addr-line>
          ,
          <country country="PL">Poland</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>We present a model of a Software De ned Network (SDN) where frequent changes in routing and tra c rates at routers are needed to respond to the security, quality of service (QoS), and energy savings requirements of applications such as the Internet of Things. Such frequent path and tra c changes introduce time-dependent network behaviours, and standard queueing models are not well adapted to analyse the transient regime, we propose a tractable di usion approximation for both the transient and steady-state behaviour. Our model can represent any network topology transmitting time-dependent ows with routing changes, and computes queue length and delay distributions at each network node and along complete paths between senders and receivers. Using realistic router parameters, we show that transients occupy a signi cant fraction of system time, so that the optimisation conducted with SDN controllers needs to include the e ect of time-dependent behaviours.</p>
      </abstract>
      <kwd-group>
        <kwd>SDN</kwd>
        <kwd>IoT Networks</kwd>
        <kwd>Security</kwd>
        <kwd>QoS</kwd>
        <kwd>Routing</kwd>
        <kwd>Transients</kwd>
        <kwd>Di usion Approximation</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>The Internet of Things (IoT) and its increasing volumes of tra c for new
services such as video related to security, server virtualisation of the Cloud and
Fog [38,8] and highly distributed data storage [22,9], create new challenges for
the Internet [26,35]. Indeed, expanding IoT applications such as Health
Monitoring [32], Smart Homes [3] and Smart Vehicles [18], create large volumes of
intermittent tra c with stringent security, QoS and energy minimisation needs
[6].</p>
      <p>Thus network structures based on static switches are not well suited to deliver
high performance, energy e ciency and reliability in such dynamically
changing environments, and are not exible enough to maintain Quality of Service
(QoS) for increasingly complex networks. On the other hand, SDN [34,39] with
intelligent programmable controllers can be aware of the overall state of nodes
and links, and dynamically manage the network and adapt to new conditions
[25]. Indeed, SDN provides exible and scalable routing for intelligent networks
[14] by separating the control and data planes for tra c engineering, link failure
recovery, load balancing [40] and security issues [41]. Thus the concentration
of network intelligence and management in SDN controllers enables innovative
smart cognitive routing [17,21] to respond by changing network paths and tra c
levels to meet the dynamic security, QoS and energy savings requirements of the
IoT.</p>
      <p>Earlier studies of SDN switches have used steady-state queueing models such
as M=M=1, M=H2=1, M=G=1, M=Geo=1, GI=M=1=K, based on Markov chains,
embedded Markov chains [29,2,36,28,16,31] or network calculus [4,5]. Thus they
do not consider the frequent tra c changes due to controller decisions. To
address this concern, we recently considered a single SDN forwarder and modelled
it with a di usion approximation [13], and considered a network of forwarders
[12] to determine its transient behaviour. These studies have shown that under
certain conditions, the transient regime can become dominant so that SDN based
optimisation should consider the e ect of transients.</p>
      <p>In SDN, paths are selected by a controller, and the SDN data plane routers
are then simple forwarding devices that follow the rules given by the controller.
An analysis of the performance of SDN switches and their cooperation with the
controller may be found in [33,27,40].</p>
      <p>Therefore this paper, we extend these studies to address a SDN based
network that supports IoT applications, and modi es its paths and tra c levels to
respond to unpredictable changes in security and QoS, so that the network has
time-dependent routing. To address this challenge we apply a di usion
approximation [24,20,30] which is well suited to investigate transient queueing problems
with general interarrival and service time distributions for realistic network data.</p>
      <p>
        The next section details the method for a single network node, while the
mathematical model of time-dependent routing in the network is presented in
Section 3 where the system equations such as (
        <xref ref-type="bibr" rid="ref12">12</xref>
        ), ... , (
        <xref ref-type="bibr" rid="ref16">16</xref>
        ) include routing
probabilities which are functions of time, leading to a novel approach in di usion
models. Numerical examples are provided in Section 4 and conclusions are drawn
in Section 5.
2
      </p>
      <p>Single Node Transient Analysis
The di usion approximation replaces the number of packets in a queueing system
by the real-valued di usion process fX(t)g 2 [0; N ] where N is the maximum
size of the queue. Following the approach in [19,23], at the extremities x = 0
and x = N of the di usion interval, two absorbing barriers are placed so that
when fX(t)g reaches a barrier, it stays there for a random time and jumps from
x = 0 to x = 1 with intensity and from x = N to x = N 1 with intensity .
The resulting di usion equation is:
dp0(t)</p>
      <p>dt
dpN (t)
dt
=
= lim [</p>
      <p>x!0 2
= lim [
x!N
2
+</p>
      <p>N + 1) ;
f (x; t; x0)]</p>
      <p>
        p0(t) ;
+ f (x; t; x0)]
pN (t) ;
(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
where (x) is the Dirac delta function, p0(t), pN (t) are probabilities that the
process is at the barrires at x = 0 or x = N , respectively, and f (x; t; x0) is
probability density function (pdf) of the process fX(t)g
f (x; t; x0)dx = P [x
      </p>
      <p>X(t) &lt; x + dx j X(0) = x0]:</p>
      <p>The incremental changes of fX(t)g, dX(t) = X(t + dt) X(t) are normally
distributed with the mean dt and variance dt where , are coe cients of
the di usion equation. The changes of the process fN (t)g during an interval
tend to normal distribution with mean ( ) and variance ( A2 3 + B2 3)
where 1= and 1= are the mean interarrival and service times, and A2, B2 are
the variances of the interarrival and service times, respectively. The choice
=
and
= A2 3 +
2 3 = CA2
B
+ CB2 ;
where CA2, CB2 are squared coe cients of variation of interarrival and service
times, assures that the changes of both processes fX(t)g and fN (t)g have normal
distributions with the same parameters.</p>
      <p>
        To determine the solution of (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) we use the following appoach from [11]. First
we consider a di usion process with two absorbing barriers at x = 0 and x = N ,
started at t = 0 from x = x0. Its probability density function (x; t; x0) has the
following form [10]:
(x; t; x0) =
8 (x
&gt;
&gt;
&gt;
&gt;
&gt;&lt; p
limx!N
where x0n = 2nN , x0n0 = 2x0 x0n :
If the initial condition is de ned by a function
(x) = 0, then the pdf of the process is
      </p>
      <p>Z N</p>
      <p>0
(x; t; ) =</p>
      <p>(x; t; ) ( )d :</p>
      <p>The probability density function f (x; t; ) of the di usion process with jumps
from the boundaries is composed of the function (x; t; ) referring to the
diffusion process before it reaches any barrier and of a spectrum of functions
t)2
t)2 o
for t = 0
for t &gt; 0 ;</p>
      <p>
        (
        <xref ref-type="bibr" rid="ref2">2</xref>
        )
(x), x 2 (0; N ), limx!0 (x) =
Z t
0
      </p>
      <p>
        Z t
0
(x; t ; 1), (x; t ; N 1) representing di usion processes with
absorbing barriers at x = 0 and x = N , started with densities g1( ) and gN 1( ) at
time &lt; t at points x = 1 and x = N 1 due to jumps from the barriers:
f (x; t; ) = (x; t; )+
g1( ) (x; t
; 1)d +
gN 1( ) (x; t
; N
1)d ;
(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )
where the densities g1( ), gN 1( ), as well as p0(t) and pN (t), are obtained from
the probability balance equations at the barriers.
      </p>
      <p>First, we compute densities 0(t), N (t) of probability that at time t the
process enters to x = 0 or x = N are
gN 1( ) N 1;0(t</p>
      <p>)d ;
gN 1( ) N 1;N (t
)d ;</p>
      <p>Z t
0
Z t</p>
      <p>0
Z
0
0(t) = p0(0) (t) + [1
p0(0)
pN (0)] ;0(t) +
g1( ) 1;0(t
)d
N (t) = pN (0) (t) + [1
p0(0)
pN (0)] ;N (t) +
g1( ) 1;N (t
)d
+</p>
      <p>Z t</p>
      <p>0
+</p>
      <p>
        Z t
0
Z
0
(
        <xref ref-type="bibr" rid="ref4">4</xref>
        )
(
        <xref ref-type="bibr" rid="ref5">5</xref>
        )
For absorbing barriers
lim
x!0
(x; t; x0) = lim
x!N
(x; t; x0) = 0 ;
hence 1;0(t) = limx!0 2 @ (@xx;t;1) : The functions ;0(t), ;N (t) denote
densities of probabilities that the initial process, started at t = 0 at the point with
density ( ) will end at time t by entering respectively x = 0 or x = N .
      </p>
      <p>Finally, we may express g1(t) and gN (t) with the use of functions 0(t) and
N (t):
where 1;0(t), 1;N (t), N 1;0(t), N 1;N (t) are densities of the rst passage time
between corresponding points, e.g.</p>
      <p>1;0(t) = lim [
x!0 2
(x; t; 1)] :
g1( ) =
0(t)l0(
t)dt ;
gN 1( ) =</p>
      <p>
        N (t)lN (
t)dt ;
(
        <xref ref-type="bibr" rid="ref6">6</xref>
        )
where l0(x), lN (x) are the densities of sojourn times in x = 0 and x = N ; the
distributions of these times are not restricted to exponential ones as it is in Eq.
(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ).
      </p>
      <p>
        Technicaly, it is easier to compute this solution in Laplace domain where
convolutions of functions become products. For any function h(t) we denote
by h(s) its Laplace transform. The Laplace transform f (x; s; ) of the density
function f (x; t; ) is
f (x; s; ) = (x; s; ) + g1(s) (x; s; 1) + gN 1(s) (x; s; N
1) ;
(
        <xref ref-type="bibr" rid="ref7">7</xref>
        )
and the Laplace transform of (x; t; x0) can be expressed as
(x; s; x0) =
where A(s) = p 2 + 2 s. For computational e ciency, we rearranged the Eq.
(
        <xref ref-type="bibr" rid="ref8">8</xref>
        ) to the form
(x; s; x0) =
      </p>
      <p>1(x x0) exp
exp[ (x x0) ]</p>
      <p>A(s)
+ 1(x0&lt;x) exp
2 sinh
xA(s)
x0A(s)
2 sinh</p>
      <p>2 sinh
x0A(s)
xA(s)</p>
      <p>x0A(s)
2 sinh
xA(s)
1
X exp
n=1
2nN</p>
      <p>A(s)</p>
      <p>H
f (t) = ln 2 X Vi f
2
where</p>
      <p>
        Vi = (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )H=2+i
min(i;H=2)
      </p>
      <p>X
k=b i+21 c</p>
      <p>
        kH=2+1(2k)!
(H=2
k)!k!(k
1)!(i
k)!(2k
i)!
H is an even integer; we used H = 16, following Stehfest's recommendations.
Theoretically (
        <xref ref-type="bibr" rid="ref10">10</xref>
        ) is an in nite series and the increase of H should increase the
accuracy of computations. However, considering the form of the functions being
inverted in our case, the values of elements of (
        <xref ref-type="bibr" rid="ref10">10</xref>
        ) become either very small or
very large with the increase of the index i and introduce numerical errors. After
some numerical experiments, we found H = 16 is satisfactory and we do not
need to introduce longer computer words for extra numerical precision.
      </p>
      <p>
        Note that the presented transient solution is valid for constant di usion
parameters. However, the values of ows, hence also model parameters, may vary
with time. Therefore in computations, we x model parameters during small
intervals (of the order of a single mean service time) and the solution at the
end of one interval determines the initial conditions (i.e. function in Eqs. (
        <xref ref-type="bibr" rid="ref3">3</xref>
        ),
(
        <xref ref-type="bibr" rid="ref7">7</xref>
        )) for the next interval.
      </p>
      <p>The delay through the queue, including waiting and service time, is
obtained as a rst passage time from an initial point taken with probability density
f (x; t; ) to the absorbing barrier placed at x = 0, see [13].</p>
      <p>It is known that lims!0 sf (s) = limt!1 f (t) if sf (s) is an analytic function
for &lt;(s) 0, therefore the above solution in form of Laplace transforms is
convergent to steady-state solution for real domain.
3</p>
      <p>Network of Nodes, Transient Analysis
Consider a network of M stations type G/G/1/N with routing probabilities
rij (t). We follow the approach of [24] developed for the steady-state network
model, then adapted to transient analysis in [15]. Here we introduce additionally,
for the needs of SDN, the time-depending routing.</p>
      <p>The rst objective of the network model is to decompose the network: to
determine the input ows at every station and then apply the single server
model of the previous section to each station separately.</p>
      <p>In the transient state, we should distinguish at any station i the input ow
i in(t) and the output ow i out(t)
i out(t) = [1
p0i(t)] i;
which are di erent. p0i(t) denotes probability that the station i is idle at time t,
i.e. the di usion process related to this station is inside the barrier at x = 0. The
term 1 p0i(t) = %i presents probability that the station i is busy and customers
are leaving it with the rate i.</p>
      <p>
        The tra c equations balancing the ows of stations are
i in(t) =
j out(t)rji(t) ;
i = 1; : : : ; M;
(
        <xref ref-type="bibr" rid="ref12">12</xref>
        )
      </p>
      <p>M
0i(t) + X
where the rst term 0i represents tra c ow coming from the outside of the
network directly to station i.</p>
      <p>
        As mentioned earlier, routing probabilities rji(t) are changing each interval
following decisions of the controler, remaining constant inside the interval,
and ow parameters may change every interval &lt; ; we assume for simplicity
= n , in numerical examples below n = 10. This way all model parameters
are constant witin intervals when the solution (
        <xref ref-type="bibr" rid="ref3">3</xref>
        ) is computed.
      </p>
      <p>
        Denote by fAj (x; t) and fBj (x; t) the density functions of interarrival and
service times distributions at station j. The pdf fDj (x; t) of the interdeparture
times from this node at time t may be expressed as
fDj (x; t) = %j (t)fBj (x; t) + [1 %j (t)]fAj (x; t) fBj (x; t) ;
j = 1; : : : ; M; (
        <xref ref-type="bibr" rid="ref13">13</xref>
        )
where * denotes the convolution. The rst term of the right side in (
        <xref ref-type="bibr" rid="ref13">13</xref>
        )
represents the interdepature times of packets when the node j is working and the
second term gives the interdeparture times when it is idle. The formula (
        <xref ref-type="bibr" rid="ref13">13</xref>
        ),
known as Burke's theorem [7], is exact for Poisson input (the pdf of the idle
period distribution that should be used in the second term of (
        <xref ref-type="bibr" rid="ref13">13</xref>
        ) is the same
as fAj (x; t)) and approximate in other cases. From (
        <xref ref-type="bibr" rid="ref13">13</xref>
        ) we receive
CD2j (t) = %j2(t)CB2j (t) + CA2j (t)(1
%j (t)) + %j (t)[1
%j (t)];
(
        <xref ref-type="bibr" rid="ref14">14</xref>
        )
where CD2j (t), CB2j (t), CA2j (t) are time-dependent square coe cients of variation
of interdeparture, service, and interarrival times, respectively. Packets leaving the
node j according to the distribution fDj (x; t) choose any node i with probability
rji(t) and the times between packets routed from node j to i has pdf fji(x; t)
fji(x; t) = fDj (x; t)rji(t) + fDj (x; t) fDj (x; t)[1
rji(t)]rji(t) +
fDj (x; t) fDj (x; t) fDj (x; t)[1
rji(t)]2rji +
(
        <xref ref-type="bibr" rid="ref15">15</xref>
        )
i.e. a packet leaving station j goes to station i with probability rji(t) or with
probability 1 rji(t) it goes elswhere but the second goes to i with
probability rji(t), hence the gap has has pdf fDj (x; t) fDj (x; t) with probability
[1 rji(t)]rji(t), etc, or, after Laplace transform
fji(s; t) = fDj (s; t)rji(t) + fDj (s; t)2[1
rji(t)]rji +
+ fDj (s; t)3(1
      </p>
      <p>rji(t))2rji +
=
1
rji(t)fi(s; t)
[1
rji(t)]fi(s; t)
;
and we compute the squared coe cient of variation</p>
      <p>
        Cj2i(t) = rji(t)[CD2j (t)
and then the parameters of the input ow at station i are given by (
        <xref ref-type="bibr" rid="ref12">12</xref>
        ) and (
        <xref ref-type="bibr" rid="ref16">16</xref>
        )
CA2i(t) =
1 M
      </p>
      <p>
        X rji(t) i out(t)[(CD2i(t) 1)rji(t)+1] +
i in(t) j=1
C02i(t) 0i(t)
i in(t)
; (
        <xref ref-type="bibr" rid="ref16">16</xref>
        )
where the parameters 0i and C02i refer to the ow coming to station i from
outside of the network.
      </p>
      <p>
        Eqs. (
        <xref ref-type="bibr" rid="ref14">14</xref>
        ), (
        <xref ref-type="bibr" rid="ref16">16</xref>
        ) form a system of linear equations yielding CA2i(t) and, in
consequence, the di usion parameters i(t), i(t) for every node i. At each interval
, functions fi(x; t; i) giving queue distributions at every station i for t 2
are computed. Their valuest at the end of the interval yield, among others, the
current utilisations %i used to determine the ow parameters and di usion
parameters for the next interval . This way the ow parameters change each
and routing changes each = n .
      </p>
      <p>The pdf fRi(x; t) of the current response time (waiting time plus service) is
determined using the rst passage time from the end of the queue to zero.</p>
      <p>The rst passage time of the di usion process from x0 to x = 0 has the
density function [10]
x0;0(t) = p
2
x0
t3
e
( t+1)2</p>
      <p>2 t ;
x0;0(s) = e x0 +
p 2+2 s
:
with the Laplace transform
The starting point x0 is determined by the function fi(x; t; i) hence
Z N</p>
      <p>0
fRi(x; t) =</p>
      <p>;0(x)fi( ; t; i)d :</p>
      <p>
        If fRi(x; t) is the response time pdf at node i, then the response time pdf
fR(x; t) for the path 1; : : : ; n of n stations is
fR(x; t) = fR1(x; t) fR2(x; t) fR3(x; t)
fRn(x; t);
or
fR(x; s) =
n
Y fRi(x; s):
i=1
The loss probability ploss(t) for same entire path may be computed from
1
ploss(t) = (1
pN1(t))(1
pN2(t))(1
pN3(t)) : : : (1
pNn(t));
(
        <xref ref-type="bibr" rid="ref17">17</xref>
        )
where pNi(t) is probabiliity that the queue at station i is saturated at time t,
i.e. the di usion process for this station is at time t at the barrier x = N .
4
      </p>
      <p>Application to a SDN and a Numerical Experiment
Since the input and output hardware of a SDN forwarder is fast, the main
component to be considered is the queue of packets waiting until the node identi es
to which ow they belong and to what output port they are to be sent. Suppose
that the identi cation requires a linear search in a ow table with K entries,
and T is the constant time to check one entry.</p>
      <p>Ler p be the probability that the router's ow table does not contain the
ow rule for a given packet; this will be discovered after going through all K
positions, i.e. after time KT . In this case, the service time is constant, with zero
variance.</p>
      <p>Otherwise, with probability (1 p), the time to nd the existing entry is
uniformly distributed in [T; KT ] and having
mean (K + 1)T =2 and variance (K2
1)T 2=12:
The two cases de ne the rst two moments 1= and B2 of service time
distribution in our G=G=1=N di usion model.</p>
      <p>We consider a network composed of four switches, represented in Fig. 1. The
network performance is investigated during 1 second. Host 1 is sending a ow of
01 packets to Host 2. The intensity of the ow is changing in the range 500 2500
packets/sec, see Fig. 2. If the ow is below 1000 packets per second, it is sent
by the direct link S1 S4, and if it exceeds the maximum capacity of this link,
the surplus is sent in equal share by paths S1 S2 S4 and S1 S3 S4.</p>
      <p>We assume at each station the bu ers of N = 100 packets; in case of S1,
S2, S3 the time to check one entry in the list of connections is T = 8 10 7
sec, and in S4 this time is twice shorter T = 4 10 7 sec. The number of entries
K = 950, p = 0. It results in 1 = 2 = 3 = 2628:8 packets/sec and 4 = 5257:6
packets/sec. Squared coe cient of variation of service time CB2i is in all stations
equal 0.33.</p>
      <p>In the interval [t = 0:450 sec, t = 0:705 sec], an additional ow 02 of the
intensity 1500 packets per second appears at station S2 and is also sent to Host
2 via S2 S4. We consider three values of the squared coe cient of variation
of interarrival times in the rst ow: CA21 = C021 = 1:02; 4:08 and 8:16. The
rst value is obtained from our analysis of CAIDA data [1], and the others were
chosen to see the network behaviour if the ow is more irregular. For the second
ow, C022 = 1:02.</p>
      <p>
        The SDN controller alters the routing to balance the load of nodes every 100
msec, hence at t = 500 msec it reacts on the presence of the second ow and
changes the routing r12 and r13, see Fig. 3. In consequence, the load of stations
S2 and S3 is changed, Fig. 4. After the end of the ow 02 the initial routing
is reestablished. The change of the utilisation in uences the parameters of the
output ows: as it is expressed by Eq. (
        <xref ref-type="bibr" rid="ref14">14</xref>
        ), higher the utilisation of a station i,
closer its squared coe cient of variation of interdeparture times CD2i(t) is to
CB2i(t) and it is less dependent on CA2i(t). Fig. 5 displays the changes of CD2i(t)
following the pattern of input ows.
      </p>
      <p>
        The transient solution of di usion equations is computed in intervals of the
length 10 msec, i.e. we have 100 intervals with xed di usion parameters; at the
end of each the equations (
        <xref ref-type="bibr" rid="ref12">12</xref>
        ), (
        <xref ref-type="bibr" rid="ref16">16</xref>
        ) are solved to determine new parameters
of ow for the single station models in the next interval. The di usion density
function obtained for any station i at the end of an interval gives initial conditions
for the di usion equation at the next one.
      </p>
      <p>The model helps us to analyse the dynamics of every node. In Fig. 6 we see
how the distribution of queue length (the queue is empty at the beginning, and
it starts to be lled) at station S1 evolves with time. Even minimal values of the
distributions are computed without numerical problems. As mentioned above,
we used three di erent values of CA21(t), the squared coe cient of variation of
interarrival times at station S1. In Fig. 7 the density function for S1 queue
distribution is displayed for these values and makes evident their impact on the
queue, note that the scale in Figs. 6, 7 is logarithmic.</p>
      <p>The next gures display the impact of CA21 on loss probability due to the
full bu er at station S1, Fig. 8, and on the mean queue at this station, Fig. 9,
following the changes of the ow intensity.</p>
      <p>The next curves compare the loss probability, Fig. 10 (note here minimal
values computed by the model), and mean queues for all four stations, Fig. 11,
in case of CA21 = 1:04. We may observe the changes in mean queues in S2 and
S3 due to load balancing after the second ow becomes active. We see also,
observing mean queues at S1 and S2, that transient periods may be longer than
the time between the controller's decisions. The length of the transient time
increases with a load of a station and variability of the input ow.</p>
      <p>Figures 12 and 13 refer to station S2. We see here a weak impact of CA21 on
the mean queue. It is evident: as this station is mainly supplied by the second
ow. However, if we consider loss probabilities which have here very small values
and are displayed in logarithmic scale, the impact of CA21 may be observed. It
is better seen at station S3, Fig. 14, and in station S4, Fig. 15, because they
receive much more of the rst ow. Note that for greater variabilities of the rst
ow, the path S1 S3 S4 becomes saturated, Fig. 16.</p>
      <p>Let us also consider a simple example of optimization. Suppose as
previously that station S1 is forwarding a ow 01 packets to nodes S2 and S3.
Station S2 is additionally receiving a ow of (0l2oc) packets directly from the
outside of the network. The controller is changing routing every = 100 msec
and needs do determine routing probabilities for the nearest , knowing current
parameters of ows at the beginning of the interval, as well as the current queue
distributions at S1, S2, S3, representing previous behaviour of the network. The
goal is to minimise the mean backlog at S2 and S3 during
The IoT provides large volumes of highly capillary tra c that includes data and
video, which has stringent QoS and security constraints. These large volumes of
tra c also create additional energy consumption in networks. Thus means are
needed to distribute tra c dynamically so that security and QoS are assured,
and energy consumpton is minimised.</p>
      <p>Fortunately, the advent of SDN allows the implementation of smart adaptive
routing [25] which allows network paths to change so that security incidents and
tra c overloads can be accomodated by taking advantage of alternate paths.
However this leads to an ineresting paradigm shift in network modeling which has
been traditionally addressed via steady-state \long term" modelling techniques.
However, when SDN intervenes dynamically to change paths and tra c levels,
the network is seldom at steady-state so that optimisation must take transients
into account.</p>
      <p>To achieve this, this paper uses di usion approximations for the performance
evaluation of a network of SDN data plane switches with time-dependent
routing. We show that this method is computationally operational, and that it can
provide quantitative results for models with realistic parameter values.</p>
      <p>Our analysis captures the interactions among the main parameters of the
network, and numerical examples display the dependence of the queue lengths
and queueing delays and their changing dynamics, on the ow intensity and
variance of interarrival times.</p>
      <p>Our approach con rms the fact that transient periods play a signi cant role
in the performance of SDN networks, and in future work we will use it to analyse
much larger networks.</p>
      <p>Fig. 4: i(t)= i for all stations
Fig. 5: S1, S2, S3: squared coe cient of variation CD2i(t) for the output ow,</p>
      <p>CA21 = 1:02</p>
      <p>Fig. 9: S1: mean queue for di erent CA21
Fig. 13: Station S2: mean queue for di erent CA21
Acknowledgements
during</p>
      <p>as a function of routing probabilities r12,
r13 = 1 r12
The work presented in this paper was partially supported by the SerIoT Research
and Innovation Action, funded by the European Commission under the
H2020IoT-2016-2017 (H2020-IoT-2017) Program through Grant Agreement 780139.
25. Gelenbe et al., E.: Self-aware networks that optimize security, qos and energy.</p>
      <p>
        Proceedings of the IEEE, accepted for publication 108(
        <xref ref-type="bibr" rid="ref7">7</xref>
        ) (2020)
26. Hakiri et al., A.: Software-de ned networking: Challenges and research
opportunities for future internet. Computer Networks 75, 453{471 (2014)
27. Kuzniar, M., Peresini, P., Kostic, D., Canini, M.: Methodology, measurement and
analysis of ow tablee update characteristics in hardware open ow switches.
Computer Networks 136, 22{36 (2018)
28. Lai, Y.C., Ali, A., Hassan, M., Hossain, S., Lin, Y.D.: Performance modeling and
analysis of tcp connections over software de ned networks. In: Proceedings of the
2017 IEEE Global Communications Conference. pp. 1{6. IEEE, Singapore (2017).
https://doi.org/10.1109/GLOCOM.2017.8254078
29. Mahmood, K., Chilwan, A., Osterbo, O., Jarschel, M.: Modelling of open ow-based
software-de ned networks: the multiple node case. IET Networks 4(
        <xref ref-type="bibr" rid="ref5">5</xref>
        ), 278{284
(2015)
30. Marin, G.A., Mang, X., Gelenbe, E., Onvural, R.O.: Statistical call admission
control. US Patent 6,222,824 (2001)
31. Miao, W., Min, G., Wu, Y., Wang, H., Hu, J.: Performance modelling and
analysis of software de ned networking under bursty multimedia tra c. ACM
Transactions on Multimedia Computing, Communications, and Applications 12(55), 24{36
(2018)
32. Natsiavas et al., P.: Comprehensive user requirements engineering methodology
for secure and interoperable health data exchange. BMC medical informatics and
decision making 18(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ), 85 (2018)
33. Nguyen-Ngoc, A., Lange, S., Geissler, S., Zinner, T., Tran-Gia, P.: Estimating the
ow rule installation time od sdn switches when facing control plane delay. LNCS
10740, 113=126 (2018)
34. Paul, S., Pan, J., Jain, R.: Architectures for the future networks and the next
generatio internet: A survey. Computer Communications 34, 2{42 (2011)
35. Rowshanrad et al., S.: A survey on sdn, the future of networking. Journal of
Advanced Computer Science &amp; Technology 3(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ), 232{248 (2014)
36. Singh et al., D.: Modelling software-de ned networking: Software and hardware
switches. Journal of Computer Network and Computer Applications 122, 24{36
(2018)
37. Stehfest, H.: Numeric inversion of laplace transform. Communication of ACM
13(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ), 47{49 (1970)
38. Wang, L., Gelenbe, E.: Adaptive dispatching of tasks in the cloud. IEEE
Transactions on Cloud Computing 6(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ), 33{45 (2018)
39. Wibowo, F.X., Gregory, M.A., Ahmen, K., Gomez, K.M.: Multi-domain software
de ned networking: Research status and challenges. Journal of Network and
Computer Applications 87, 32{45 (2017)
40. Wu, K.R., Liang, J.M., Lee, S.C., Tseng, Y.C.: E cient and consistent ow update
for software de ned networks. IEEE Journal on Selected Areas in Communications
36(
        <xref ref-type="bibr" rid="ref3">3</xref>
        ), 411{420 (2018)
41. Yoon, C., Park, T., Lee, S., Kang, H., Shin, S., Zhang, Z.: Enabling security
functions with sdn: A feasibility study. Computer Networks 85, 19{35 (2015)
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1. https://data.caida.org/datasets/passive-2016/equinix-chicago/ 20160218-
          <fpage>130000</fpage>
          .UTC/
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Ansell</surname>
            et al.,
            <given-names>J.</given-names>
          </string-name>
          :
          <article-title>Making queueing theory more palatable to sdn/open ow-based network practitioners</article-title>
          .
          <source>In: Proceedings of the 2016 IEEE/IFIP Network Operations and Management Symposium</source>
          . pp.
          <volume>1119</volume>
          {
          <fpage>1124</fpage>
          . IEEE, Istanbul, Turkey (
          <year>2016</year>
          ). https://doi.org/10.1109/NOMS.
          <year>2016</year>
          .7502973
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Augusto-Gonzalez</surname>
            et al.,
            <given-names>J.</given-names>
          </string-name>
          :
          <article-title>From internet of threats to internet of things: A cyber security architecture for smart homes</article-title>
          .
          <source>In: 2019 IEEE 24th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks (CAMAD)</source>
          . pp.
          <volume>1</volume>
          {
          <issue>6</issue>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Azodolmolky</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wieder</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yahyapour</surname>
          </string-name>
          , R.:
          <article-title>Performance evaluation of a scalable software-de ned networking deployment</article-title>
          .
          <source>In: Proceedings of the 2013 Second European Workshop on Software De ned Networks</source>
          . pp.
          <volume>68</volume>
          {
          <fpage>74</fpage>
          . IEEE, Berlin, Germany (
          <year>2013</year>
          ). https://doi.org/10.1109/EWSDN.
          <year>2013</year>
          .18
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Azodolmolky</surname>
            et al.,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>An analytical model for software de ned networking: A network calculus-based approach</article-title>
          .
          <source>In: Proceedings of the IEEE Global Communications Conference</source>
          . pp.
          <volume>1397</volume>
          {
          <fpage>1402</fpage>
          . IEEE, Atlanta, USA (
          <year>2013</year>
          ). https://doi.org/10.1109/GLOCOM.
          <year>2013</year>
          .6831269
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Baldini</surname>
            et al.,
            <given-names>G.</given-names>
          </string-name>
          :
          <article-title>Iot network risk assessment and mitigation: The seriot approach</article-title>
          . In: Soldatos,
          <string-name>
            <surname>J</surname>
          </string-name>
          . (ed.)
          <article-title>Security Risk Management for the Internet of Things: Technologies and Techniques for IoT Security, Privacy and Data Protection</article-title>
          . p.
          <volume>88</volume>
          {
          <fpage>104</fpage>
          . Now Publishers (
          <year>2020</year>
          ). https://doi.org/DOI: 10.1561/9781680836837
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Burke</surname>
            ,
            <given-names>P.J.:</given-names>
          </string-name>
          <article-title>The output of a queuing system</article-title>
          .
          <source>Operations Research</source>
          <volume>4</volume>
          (
          <issue>6</issue>
          ),
          <volume>699</volume>
          {
          <fpage>704</fpage>
          (
          <year>1956</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Buyya</surname>
            et al.,
            <given-names>R.:</given-names>
          </string-name>
          <article-title>A manifesto for future generation cloud computing: Research directions for the next decade</article-title>
          .
          <source>ACM Computing Surveys (CSUR) 51(5)</source>
          ,
          <volume>1</volume>
          {
          <fpage>38</fpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Chesnais</surname>
            et al.,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>On the modeling of parallel access to shared data</article-title>
          .
          <source>Communications of the ACM</source>
          <volume>26</volume>
          (
          <issue>3</issue>
          ),
          <volume>196</volume>
          {
          <fpage>202</fpage>
          (
          <year>1983</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Cox</surname>
            ,
            <given-names>R.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Miller</surname>
            ,
            <given-names>H.D.</given-names>
          </string-name>
          :
          <source>The Theory of Stochastic Processes. Chapman and Hall</source>
          , London, UK (
          <year>1965</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Czachorski</surname>
          </string-name>
          , T.:
          <article-title>A method to solve di usion equation with instantaneous return processes acting as boundary conditions</article-title>
          .
          <source>Bulletin of Polish Academy of Sciences, Technical Sciences 41(4)</source>
          (
          <year>1993</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Czachorski</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gelenbe</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuaban</surname>
            ,
            <given-names>G.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Marek</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Dynamics of software dened networks, di usion model</article-title>
          . Submitted to:
          <source>Journal of Physics: Conference Series</source>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Czachorski</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gelenbe</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuaban</surname>
            ,
            <given-names>G.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Marek</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Transient behaviour of a network router, accepted</article-title>
          . In: Herencsar,
          <string-name>
            <given-names>N.</given-names>
            ,
            <surname>Benedetto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            ,
            <surname>Hosek</surname>
          </string-name>
          ,
          <string-name>
            <surname>J</surname>
          </string-name>
          . (eds.)
          <source>Proceedings of International Conference on Telecommunications and Signal Processing TSP</source>
          <year>2020</year>
          ,
          <article-title>submitted</article-title>
          . IEEE,
          <string-name>
            <surname>Milano</surname>
          </string-name>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Dobson</surname>
            et al.,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>A survey of autonomic communications</article-title>
          .
          <source>ACM Transactions on Autonomous and Adaptive Systems (TAAS) 1</source>
          (
          <issue>2</issue>
          ),
          <volume>223</volume>
          {
          <fpage>259</fpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Duda</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Di usion approximations for time-dependent queueing systems</article-title>
          .
          <source>IEEE Journal on Selected Areas in Communications 4</source>
          ,
          <issue>905</issue>
          {
          <fpage>918</fpage>
          (
          <year>1986</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Fahmin</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lai</surname>
            ,
            <given-names>Y.C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hossain</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lin</surname>
            ,
            <given-names>Y.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Saha</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Performance modeling of sdn with nfv under or aside the controller</article-title>
          .
          <source>In: Proceedings of the 5th International Conference on Future Internet of Things and Cloud Workshops</source>
          . pp.
          <volume>211</volume>
          {
          <fpage>216</fpage>
          . IEEE, Prague (
          <year>2017</year>
          ). https://doi.org/10.1109/FiCloudW.
          <year>2017</year>
          .76
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Francois</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gelenbe</surname>
          </string-name>
          , E.:
          <article-title>Towards a cognitive routing engine for software de ned networks</article-title>
          .
          <source>In: Proceedings of the 2016 IEEE International Conference on Communications</source>
          . pp.
          <volume>1</volume>
          {
          <issue>6</issue>
          . IEEE,
          <string-name>
            <surname>Kuala Lumpur</surname>
          </string-name>
          (
          <year>2016</year>
          ). https://doi.org/10.1109/ICC.
          <year>2016</year>
          .7511138
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18. Frotscher et al.,
          <string-name>
            <surname>A.</surname>
          </string-name>
          :
          <article-title>Improve cybersecurity of c-its road side infrastructure installations: the seriot-secure and safe iot approach</article-title>
          .
          <source>In: 2019 IEEE International Conference on Connected Vehicles and Expo (ICCVE)</source>
          . pp.
          <volume>1</volume>
          {
          <issue>5</issue>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Gelenbe</surname>
          </string-name>
          , E.:
          <article-title>On approximate computer system models</article-title>
          .
          <source>J. of the ACM</source>
          <volume>22</volume>
          (
          <issue>2</issue>
          ),
          <volume>261</volume>
          {
          <fpage>269</fpage>
          (
          <year>1975</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Gelenbe</surname>
          </string-name>
          , E.:
          <article-title>Probabilistic models of computer systems part ii: Di usion approximations, waiting times and batch arrivals</article-title>
          .
          <source>Acta Informatica</source>
          <volume>12</volume>
          ,
          <issue>285</issue>
          {
          <fpage>303</fpage>
          (
          <year>1979</year>
          ), https://doi.org/10.1007/BF00268317
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Gelenbe</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Domanska</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Czachorski</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Drosou</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tzovaras</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Security for internet of things: The seriot project</article-title>
          .
          <source>In: 2018 International Symposium on Networks, Computers and Communications (ISNCC)</source>
          . pp.
          <volume>1</volume>
          {
          <issue>5</issue>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Gelenbe</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hebrail</surname>
          </string-name>
          , G.:
          <article-title>A probability model of uncertainty in data bases</article-title>
          .
          <source>In: 1986 IEEE Second International Conference on Data Engineering</source>
          . pp.
          <volume>328</volume>
          {
          <fpage>333</fpage>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>1986</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Gelenbe</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mang</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Onvural</surname>
          </string-name>
          , R.:
          <article-title>Di usion based statistical call admission control in atm</article-title>
          .
          <source>Performance evaluation 27</source>
          ,
          <volume>411</volume>
          {
          <fpage>436</fpage>
          (
          <year>1996</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Gelenbe</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pujolle</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          :
          <article-title>The behaviour of a single-queue in a general queueing network</article-title>
          .
          <source>Acta Inf</source>
          .
          <volume>7</volume>
          ,
          <issue>123</issue>
          {
          <fpage>136</fpage>
          (
          <year>1976</year>
          ). https://doi.org/10.1007/BF00265766, https://doi.org/10.1007/BF00265766
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>