...
首页> 外文期刊>IEEE transactions on information forensics and security >A Policy-Based Security Architecture for Software-Defined Networks
【24h】

A Policy-Based Security Architecture for Software-Defined Networks

机译:用于软件定义网络的基于策略的安全体系结构

获取原文
获取原文并翻译 | 示例
           

摘要

As networks expand in size and complexity, they pose greater administrative and management challenges. Software-defined networks (SDNs) offer a promising approach to meeting some of these challenges. In this paper, we propose a policy-driven security architecture for securing end-to-end services across multiple SDN domains. We develop a language-based approach to design security policies that are relevant for securing SDN services and communications. We describe the policy language and its use in specifying security policies to control the flow of information in a multi-domain SDN. We demonstrate the specification of fine-grained security policies based on a variety of attributes, such as parameters associated with users and devices/switches, context information, such as location and routing information, and services accessed in SDN as well as security attributes associated with the switches and controllers in different domains. An important feature of our architecture is its ability to specify path- and flow-based security policies that are significant for securing end-to-end services in SDNs. We describe the design and the implementation of our proposed policy-based security architecture and demonstrate its use in scenarios involving both intra- and inter-domain communications with multiple SDN controllers. We analyze the performance characteristics of our architecture as well as discuss how our architecture is able to counteract various security attacks. The dynamic security policy-based approach and the distribution of corresponding security capabilities intelligently as a service layer that enables flow-based security enforcement and protection of multitude of network devices against attacks are important contributions of this paper.
机译:随着网络规模和复杂性的扩展,它们带来了更大的管理和管理挑战。软件定义网络(SDN)提供了一种有前途的方法来应对其中一些挑战。在本文中,我们提出了一种策略驱动的安全体系结构,用于跨多个SDN域保护端到端服务。我们开发了一种基于语言的方法来设计与SDN服务和通信安全相关的安全策略。我们描述策略语言及其在指定安全策略中的用途,以控制多域SDN中的信息流。我们演示了基于各种属性的细粒度安全策略的规范,例如与用户和设备/交换机关联的参数,上下文信息(例如位置和路由信息)以及在SDN中访问的服务以及与NET相关的安全属性不同域中的交换机和控制器。我们架构的一个重要功能是它能够指定基于路径和流的安全策略,这些策略对于保护SDN中的端到端服务非常重要。我们描述了我们提出的基于策略的安全体系结构的设计和实现,并演示了它在涉及与多个SDN控制器进行域内和域间通信的情况下的用法。我们分析了架构的性能特征,并讨论了架构如何抵御各种安全攻击。基于动态安全策略的方法以及将相应安全功能作为服务层进行智能分配,可以实现基于流的安全实施并保护众多网络设备免受攻击,这是本文的重要贡献。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号