【24h】

Checking Multi-domain Policies in SDN

机译:在SDN中检查多域策略

获取原文
       

摘要

Programmable Network like SDN allows administrators to program network nfrastructure according to service demand and custom-defined policies. Network olicies are interpreted by the centralized controller to define actions and rules to rocess the network traffic on devices that belong to a single domain. However, actual etworks are multi-domain where several domains are interconnected. Then, because DN controllers in a domain cannot define nor monitor policies in other domains, etwork administrators cannot ensure that their own policies, origin policies are being nforced by the domains not directly managed by them (i.e. foreign domains). e present AudiT, a multi-domain SDN policy verifier that identifies whether an rigin policy is enforced by foreign domains. AudiT comprises (1) model for network opology, policies, and flows, (2) an Audit protocol to gather information about the ctions performed by network devices to carry the flows of interest, and (3) a validation ngine that takes that information and detects security policy violations, and (4) an extension to the OpenFlow protocol to enable external auditing. This paper resents our approach and illustrates its application using an example considering ultiple SDN networks.
机译:像SDN这样的可编程网络使管理员可以根据服务需求和自定义策略对网络基础结构进行编程。网络策略由集中控制器解释,以定义操作和规则来处理属于单个域的设备上的网络流量。但是,实际的etworks是多域,其中多个域相互连接。然后,由于域中的DN控制器无法定义或监视其他域中的策略,因此工作管理员无法确保自己的策略,源策略受到不是由它们直接管理的域(即,外部域)的强制。当前的AudiT是一个多域SDN策略验证程序,用于标识外来域是否实施了原始策略。 AudiT包括(1)用于网络拓扑,策略和流的模型,(2)审核协议,以收集有关网络设备执行以承载感兴趣的流的功能的信息,以及(3)接受该信息的验证引擎,以及检测违反安全策略的行为,以及(4)对OpenFlow协议的扩展以启用外部审核。本文对我们的方法表示不满,并通过考虑多个SDN网络的示例说明了其应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号