首页> 外文期刊>IEEE/ACM Transactions on Networking >Efficient Network Security Policy Enforcement With Policy Space Analysis
【24h】

Efficient Network Security Policy Enforcement With Policy Space Analysis

机译:通过策略空间分析实现有效的网络安全策略执行

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Network operators rely on security services to protect their IT infrastructures. Different kinds of network security policies are defined globally and distributed among multiple security middleboxes deployed in networks. However, due to the complexity of security policy, it is inefficient to directly employ existing path-wise enforcement approaches. This paper models the enforcement of network security policy as the set-covering problem, and designs a computational-geometry-based policy space analysis (PSA) tool for set operations of security policy. Leveraging the PSA, this paper first investigates the topological characteristics of different types of policies. This heuristic information reveals intrinsic complexities of security policy and guides the design of our enforcement approach. Then the paper proposes a scope-wise policy enforcement algorithm that selects a modest number of enforcement network nodes to deploy multiple policy subsets in a greedy manner. This approach can be employed on network topologies of both datacenter and service provider. The efficiencies of the PSA tool and the enforcement algorithm are also evaluated. Compared with the header space analysis, the PSA achieves much better memory and time efficiencies on set operations of security policy. Additionally, the proposed enforcement algorithm is able to guarantee network security within a reasonable number of enforcement network nodes, without introducing many extra rules.
机译:网络运营商依靠安全服务来保护其IT基础架构。全局定义了不同种类的网络安全策略,并将其分布在网络中部署的多个安全中间盒中。但是,由于安全策略的复杂性,直接采用现有的按路径执行的方法效率低下。本文将网络安全策略的实施建模为集覆盖问题,并设计了用于计算安全策略集操作的基于计算几何的策略空间分析(PSA)工具。利用PSA,本文首先研究了不同类型策略的拓扑特征。这些启发式信息揭示了安全策略的内在复杂性,并指导了我们执行方法的设计。然后,本文提出了一种基于范围的策略执行算法,该算法选择少量的执行网络节点以贪婪的方式部署多个策略子集。可以在数据中心和服务提供商的网络拓扑上采用此方法。还评估了PSA工具和实施算法的效率。与标头空间分析相比,PSA在安全策略的设置操作上实现了更好的内存和时间效率。另外,提出的实施算法能够在合理数量的实施网络节点内保证网络安全,而无需引入许多额外规则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号