...
首页> 外文期刊>Information Sciences: An International Journal >Leveraging software-defined networking for security policy enforcement
【24h】

Leveraging software-defined networking for security policy enforcement

机译:利用软件定义的网络实施安全策略

获取原文
获取原文并翻译 | 示例
           

摘要

Network operators employ a variety of security policies for protecting the data and services. However, deploying these policies in traditional network is complicated and security vulnerable due to the distributed network control and lack of standard control protocol. Software-defined network provides an ideal paradigm to address these challenges by separating control plane and data plane, and exploiting the logically centralized control. In this paper, we focus on taking the advantage of software-defined networking for security policies enforcement. We propose a two layer OpenFlow switch topology designed to implement security policies, which considers the limitation of flow table size in a single switch, the complexity of configuring security policies to these switches, and load balance among these switches. Furthermore, we introduce a safe way to update the configuration of these switches one by one for better load balance when traffic distribution changes. Specifically, we model the update process as a path in a graph, in which each node represents a security policy satisfied configuration, and each edge represents a single step of safely update. Based on this model, we design a heuristic algorithm to find an optimal update path in real time. Simulations of the update scheme show that our proposed algorithm is effective and robust under an extensive range of conditions. (C) 2015 Elsevier Inc. All rights reserved.
机译:网络运营商采用各种安全策略来保护数据和服务。但是,由于分布式网络控制和缺乏标准控制协议,在传统网络中部署这些策略非常复杂且安全性很差。软件定义的网络通过分离控制平面和数据平面,并利用逻辑上集中的控制,提供了解决这些挑战的理想范例。在本文中,我们专注于利用软件定义的网络来实施安全策略。我们提出了一种旨在实施安全策略的两层OpenFlow交换机拓扑,其中考虑了单个交换机中流表大小的限制,为这些交换机配置安全策略的复杂性以及这些交换机之间的负载平衡。此外,我们介绍了一种安全的方式来逐一更新这些交换机的配置,以在流量分配发生变化时更好地实现负载平衡。具体来说,我们将更新过程建模为图形中的路径,其中每个节点代表安全策略满足的配置,每个边缘代表安全更新的单个步骤。基于此模型,我们设计了一种启发式算法来实时找到最佳更新路径。更新方案的仿真表明,我们提出的算法在广泛的条件下都是有效且健壮的。 (C)2015 Elsevier Inc.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号