首页> 外文学位 >Policy Conflict Management in Distributed SDN Environments
【24h】

Policy Conflict Management in Distributed SDN Environments

机译:分布式SDN环境中的策略冲突管理

获取原文
获取原文并翻译 | 示例

摘要

The ease of programmability in Software-Defined Networking (SDN) makes it a great platform for implementation of various initiatives that involve application deployment, dynamic topology changes, and decentralized network management in a multi-tenant data center environment. However, implementing security solutions in such an environment is fraught with policy conflicts and consistency issues with the hardness of this problem being affected by the distribution scheme for the SDN controllers.;In this dissertation, a formalism for flow rule conflicts in SDN environments is introduced. This formalism is realized in Brew, a security policy analysis framework implemented on an OpenDaylight SDN controller. Brew has comprehensive conflict detection and resolution modules to ensure that no two flow rules in a distributed SDN-based cloud environment have conflicts at any layer; thereby assuring consistent conflict-free security policy implementation and preventing information leakage. Techniques for global prioritization of flow rules in a decentralized environment are presented, using which all SDN flow rule conflicts are recognized and classified. Strategies for unassisted resolution of these conflicts are also detailed. Alternately, if administrator input is desired to resolve conflicts, a novel visualization scheme is implemented to help the administrators view the conflicts in an aesthetic manner. The correctness, feasibility and scalability of the Brew proof-of-concept prototype is demonstrated. Flow rule conflict avoidance using a buddy address space management technique is studied as an alternate to conflict detection and resolution in highly dynamic cloud systems attempting to implement an SDN-based Moving Target Defense (MTD) countermeasures.
机译:软件定义网络(SDN)的易编程性使其成为在多租户数据中心环境中实施各种计划(包括应用程序部署,动态拓扑更改和分散式网络管理)的理想平台。然而,在这样的环境中实施安全解决方案充满了策略冲突和一致性问题,并且该问题的严重性受到SDN控制器分配方案的影响。 。这种形式是在Brew(一种在OpenDaylight SDN控制器上实现的安全策略分析框架)中实现的。 Brew具有全面的冲突检测和解决模块,以确保基于SDN的分布式云环境中的两个流规则在任何层均不存在冲突。从而确保一致的无冲突安全策略实施并防止信息泄漏。提出了一种在分散的环境中对流规则进行全局优先排序的技术,使用该技术可以识别和分类所有SDN流规则冲突。还详细介绍了无助解决这些冲突的策略。或者,如果需要管理员输入来解决冲突,则可以实施一种新颖的可视化方案来帮助管理员以美学的方式查看冲突。演示了Brew概念验证原型的正确性,可行性和可扩展性。在尝试实现基于SDN的移动目标防御(MTD)对策的高动态云系统中,研究了使用伙伴地址空间管理技术避免流规则冲突的方法,以替代冲突检测和解决方法。

著录项

  • 作者

    Pisharody, Sandeep.;

  • 作者单位

    Arizona State University.;

  • 授予单位 Arizona State University.;
  • 学科 Computer science.;Intellectual property.
  • 学位 Ph.D.
  • 年度 2017
  • 页码 150 p.
  • 总页数 150
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号