首页> 外文期刊>Computers & Security >A security policy model transformation and verification approach for software defined networking
【24h】

A security policy model transformation and verification approach for software defined networking

机译:软件定义网络的安全策略模型转换和验证方法

获取原文
获取原文并翻译 | 示例

摘要

Software-defined networking (SDN) has been increasingly utilized to enforce the security of complex networks. However SDN-based security enforcement mechanisms rely heavily on some specific security policies containing underlying network information. Facing the increasingly complex and huge SDN networks, we urgently need a novel security policy management mechanism which can be completely transparent to any underlying network information. That is it can permit network managers to define the high-level security policy model without containing any underlying information, and by means of model transformation, high-level security policy model can be automatically transformed into its corresponding lower-level security policy model containing underlying information. Moreover, we must ensure the system model of data plane updated by the low-level security policy model can hold all of security properties defined in high-level security policy model. Based on these insights, we propose a security policy model transformation and verification approach for SDN in this paper. We first specify the security policies used in SDN networks as a formal security policy model (SPM). Then we establish the system model of SDN's data plane and the mapping rules between the policy objects of SPM and the system objects of system model of data plane. Based on these mapping rules, we propose a security policy model transformation mechanism which transforms SPM into the low-level security policy model, RSPM. In order to verify the system model of data plane updated by RSPM can hold all of security properties defined in SPM, we propose a security policy verification mechanism based on model checking techniques and a group of validation conditions. Finally, we utilize a comprehensive case to illustrate the feasibility of this approach.
机译:软件定义的网络(SDN)越来越多地利用来强制执行复杂网络的安全性。然而,基于SDN的安全强制执行机制严重依赖于包含底层网络信息的某些特定的安全策略。面对越来越复杂和巨大的SDN网络,我们迫切需要一种新的安全策略管理机制,可以对任何底层网络信息完全透明。这是它可以允许网络管理员定义高级安全策略模型而不包含任何底层信息,并且通过模型转换,高级安全策略模型可以自动转换为其底层的相应的较低级别安全策略模型信息。此外,我们必须确保低级安全策略模型更新的数据平面系统模型可以保存在高级安全策略模型中定义的所有安全性属性。基于这些见解,我们提出了本文中SDN的安全策略模型转换和验证方法。我们首先指定SDN网络中使用的安全策略作为正式的安全策略模型(SPM)。然后我们建立SDN数据平面的系统模型和SPM策略对象与数据平面系统模型的系统对象之间的映射规则。基于这些映射规则,我们提出了一种安全策略模型转换机制,将SPM转换为低级安全策略模型RSPM。为了验证由RSPM更新的数据平面的系统模型可以保存SPM中定义的所有安全性属性,我们提出了一种基于模型检查技术和一组验证条件的安全策略验证机制。最后,我们利用了全面的情况来说明这种方法的可行性。

著录项

  • 来源
    《Computers & Security》 |2021年第1期|102089.1-102089.12|共12页
  • 作者单位

    College of Computer Science and Technology Nanjing University of Aeronautics and Astronautics Nanjing 211106 China;

    College of Computer Science and Technology Nanjing University of Aeronautics and Astronautics Nanjing 211106 China;

    College of Computer Science and Technology Nanjing University of Aeronautics and Astronautics Nanjing 211106 China;

    School of Computer Science and Technology Nanjing University of Posts and Telecommunications Nanjing 210023 China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    SDN; Security policy model; Model transformation; Security policy verification; Model checking;

    机译:SDN;安全策略模型;模型转化;安全政策验证;模型检查;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号