arrow
返回

Brew: A Security Policy Analysis Framework for Distributed SDN-Based Cloud Environments

delete2019-11-01
delete32
delete
OA
AI
DOI:10.1109/TDSC.2017.2726066delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
The ease of programmability in Software-Defined Networking (SDN) makes it a great platform implementation of various initiatives that involve application deployment, dynamic topology changes, and decentralized network management in a multi-tenant data center environment. However, implementing security solutions in such an environment is fraught with policy conflicts and consistency issues with the hardness of this problem being affected by the distribution scheme for the SDN controllers. In this paper we present Brew, a security policy analysis framework implemented on an OpenDaylight SDN controller, that has comprehensive conflict detection and resolution modules to ensure that no two flow rules in a distributed SDN-based cloud environment have conflicts at any layer; thereby assuring consistent conflict-free security policy implementation and preventing information leakage. We present techniques for global prioritization of flow rules in a decentralized environment, extend firewall rule conflict classification from a traditional environment to SDN flow rule conflicts by recognizing and classifying conflicts stemming from cross-layer conflicts and provide strategies for unassisted resolution of these conflicts. Alternately, if administrator input is desired to resolve conflicts, a novel visualization scheme is implemented to help the administrators view the conflicts graphically. We demonstrate the correctness, feasibility and scalability of our framework through a proof-of-concept prototype.
Keyword:
Security
Cloud computing
Control systems
Visualization
Virtual private networks
Topology
Open systems
Software-defined networks
network security
flow rule conflicts
distributed environments
data center network
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.4K
被引数:
9.6K

机构

A
Arizona State University
学者数:
2.7W
论文数: 2.5W
被引数: 4.2W