首页> 外文会议>International Symposium on Pervasive Systems, Algorithms and Networks >StateFit: A Security Framework for SDN Programmable Data Plane Model
【24h】

StateFit: A Security Framework for SDN Programmable Data Plane Model

机译:StateFit:SDN可编程数据平面模型的安全框架

获取原文

摘要

The programmable data plane model of software-defined networks (SDN) continues to gain adoption and support in many enterprise entities such as Google and Barefoot. This leading trend promises to enable flexible mechanisms for handling traffic on SDN switches. In the early stage of its development, few already-in-market proposals exploit the innovative features of a programmable data plane model to provide smart filters on the SDN switches against attack traffic if any. In this work, we therefore propose a security framework, so-called StateFit, which can flexibly filter attack traffic at the SDN programmable switches (data plane). The goal of StateFit is to reduce the latency and the signaling overhead that come along with the centralized architecture of SDN controllers and further provide innovative features for localized security services such as stateful monitoring. The experiment shows that our system is able to not only detect and prevent the attack traffic but also flexibly update the filtering policies and even the whole traffic interpreter onto the connected programmable switches. Following this approach, we believe that the vision of on-demand security services may come true soon.
机译:软件定义网络(SDN)的可编程数据平面模型继续在许多企业实体(如Google和Barefoot)中获得采用和支持。这一领先的趋势使得能够实现灵活的机制来处理SDN交换机上的流量。在其开发的早期阶段,很少有市场提案利用可编程数据平面模型的创新功能,以便在SDN交换机上提供攻击流量的智能过滤器。因此,我们提出了一种安全框架,所谓的立式机构,可以灵活地滤除SDN可编程交换机(数据平面)的攻击流量。 StateFit的目标是减少随着SDN控制器的集中式架构以及的延迟和信号开销,并进一步为本地化安全服务提供创新功能,例如有状态监控。实验表明,我们的系统不仅可以检测和防止攻击流量,而且灵活更新过滤策略,甚至整个流量解释器在连接的可编程交换机上。在这种方法之后,我们认为,按需安全服务的愿景可能很快就会实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号