首页> 外文期刊>IEEE transactions on information forensics and security >Automated Permission Model Generation for Securing SDN Control-Plane
【24h】

Automated Permission Model Generation for Securing SDN Control-Plane

机译:用于保护SDN控制平面的自动权限模型生成

获取原文
获取原文并翻译 | 示例

摘要

An important consideration in software-defined networks (SDNs), is that one SDN application, through a bug or API misuse, can break an entire SDN. While previous works have tried to mitigate such concerns by implementing access control mechanisms (permission models) for an SDN controller, they commonly require serious manual efforts in creating a permission model. Moreover, they do not support flexible permission models, and they are often tightly coupled with a specific SDN controller. To address such limitations, we introduce an automated permission generation and verification system called VOGUE. A distinguishing aspect of VOGUE is that it automatically generates flexible permission models and yet is completely separated from the SDN controller implementation. To demonstrate the feasibility of our approach, we implement a prototype, evaluate its completeness and soundness, and examine its performance. In addition, to show the effectiveness of VOGUE, we demonstrate its use cases and security impact to SDN in the context of popular SDN controllers.
机译:在软件定义网络(SDN)中,一个重要的考虑因素是,一个SDN应用程序会由于错误或API的滥用而破坏整个SDN。尽管先前的工作试图通过为SDN控制器实现访问控制机制(权限模型)来减轻此类担忧,但它们通常需要在创建权限模型时进行大量的人工工作。而且,它们不支持灵活的权限模型,并且通常与特定的SDN控制器紧密结合。为了解决这些限制,我们引入了称为VOGUE的自动权限生成和验证系统。 VOGUE的与众不同之处在于,它可以自动生成灵活的权限模型,并且与SDN控制器实现完全分开。为了证明我们方法的可行性,我们实现了一个原型,评估其完整性和可靠性,并检查其性能。另外,为了展示VOGUE的有效性,我们在流行的SDN控制器的背景下演示了它的用例和对SDN的安全性影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号