首页> 外文会议>IFIP/IEEE Symposium on Integrated Network and Service Management >Automated Factorization of Security Chains in Software-Defined Networks
【24h】

Automated Factorization of Security Chains in Software-Defined Networks

机译:软件定义网络中安全链的自动分解

获取原文

摘要

Software-defined networking (SDN) offers new perspectives with respect to the programmability of networks and services. In particular in the area of security management, it may serve as a support for building and deploying security chains in order to protect devices that may have limited resources. These security chains are typically composed of different security functions, such as firewalls, intrusion detection systems, or data leakage prevention mechanisms. In previous work, we suggested the use of techniques for learning automata as a basis for generating security chains. However, the complexity and the high number of these chains induce significant deployment and orchestration costs. In this paper, we propose and evaluate algorithms for merging and simplifying these security chains in software-defined networks, while keeping acceptable accuracy. We first describe the overall system supporting the generation and factorization of the security chains. We then present the different algorithms supporting their merging, and finally we evaluate the solution through an extensive set of experiments.
机译:软件定义网络(SDN)在网络和服务的可编程性方面提供了新的观点。特别是在安全管理领域,它可以作为构建和部署安全链的支持,以保护可能具有有限资源的设备。这些安全链通常由不同的安全功能组成,例如防火墙,入侵检测系统或数据泄漏防护机制。在以前的工作中,我们建议使用学习自动机的技术作为生成安全链的基础。但是,这些链的复杂性和数量众多,导致大量的部署和编排成本。在本文中,我们提出并评估了在保持软件定义的网络精度的同时,合并和简化这些安全链的算法。我们首先描述支持安全链生成和分解的整个系统。然后,我们介绍支持它们合并的不同算法,最后,我们通过一系列实验评估解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号