首页> 外文会议>International Conference on Computing, Networking and Communications >SUPC: SDN enabled Universal Policy Checking in Cloud Network
【24h】

SUPC: SDN enabled Universal Policy Checking in Cloud Network

机译:SUPC:SDN在云网络中启用了通用策略检查

获取原文

摘要

Multi-tenant cloud networks have various security and monitoring service functions (SFs) that constitute a service function chain (SFC) between two endpoints. SF rule ordering overlaps and policy conflicts can cause increased latency, service disruption and security breaches in cloud networks. Software Defined Network (SDN) based Network Function Virtualization (NFV) has emerged as a solution that allows dynamic SFC composition and traffic steering in a cloud network. We propose an SDN enabled Universal Policy Checking (SUPC) framework, to provide 1) Flow Composition and Ordering by translating various SF rules into the OpenFlow format. This ensures elimination of redundant rules and policy compliance in SFC. 2) Flow conflict analysis to identify conflicts in header space and actions between various SF rules. Our results show a significant reduction in SF rules on composition. Additionally, our conflict checking mechanism was able to identify several rule conflicts that pose security, efficiency, and service availability issues in the cloud network.
机译:多租户云网络具有各种安全和监视服务功能(SF),它们构成了两个端点之间的服务功能链(SFC)。 SF规则顺序重叠和策略冲突会导致云网络中的延迟增加,服务中断和安全漏洞。基于软件定义网络(SDN)的网络功能虚拟化(NFV)已经成为一种解决方案,可在云网络中实现动态SFC组合和流量控制。我们提出了一个支持SDN的通用策略检查(SUPC)框架,以通过将各种SF规则转换为OpenFlow格式来提供1)流组成和排序。这样可确保消除SFC中的冗余规则和策略合规性。 2)流冲突分析,以识别报头空间中的冲突以及各种SF规则之间的动作。我们的结果表明,SF构图规则显着减少。此外,我们的冲突检查机制能够识别出几个规则冲突,这些规则冲突在云网络中造成了安全性,效率和服务可用性问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号