A Policy-Based Security Architecture for Software-Defined Networks

被引:60
|
作者
Varadharajan, Vijay [1 ]
Karmakar, Kallol [1 ]
Tupakula, Uday [1 ]
Hitchens, Michael [2 ]
机构
[1] Univ Newcastle, Sch Elect Engn & Comp, Callaghan, NSW 2308, Australia
[2] Macquarie Univ, Dept Comp, Fac Sci & Engn, Sydney, NSW 2109, Australia
关键词
Software defined networking (SDN) security; security policies; security architecture; inter-domain security;
D O I
10.1109/TIFS.2018.2868220
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As networks expand in size and complexity, they pose greater administrative and management challenges. Software-defined networks ( SDNs) offer a promising approach to meeting some of these challenges. In this paper, we propose a policy-driven security architecture for securing end-to-end services across multiple SDN domains. We develop a languagebased approach to design security policies that are relevant for securing SDN services and communications. We describe the policy language and its use in specifying security policies to control the flow of information in a multi-domain SDN. We demonstrate the specification of fine-grained security policies based on a variety of attributes, such as parameters associated with users and devices/switches, context information, such as location and routing information, and services accessed in SDN as well as security attributes associated with the switches and controllers in different domains. An important feature of our architecture is its ability to specify path-and flow-based security policies that are significant for securing end-to-end services in SDNs. We describe the design and the implementation of our proposed policy-based security architecture and demonstrate its use in scenarios involving both intra-and inter-domain communications with multiple SDN controllers. We analyze the performance characteristics of our architecture as well as discuss how our architecture is able to counteract various security attacks. The dynamic security policy-based approach and the distribution of corresponding security capabilities intelligently as a service layer that enables flow-based security enforcement and protection of multitude of network devices against attacks are important contributions of this paper.
引用
收藏
页码:897 / 912
页数:16
相关论文
共 50 条
  • [1] Analysis of Policy-Based Security Management System in Software-Defined Networks
    Sood, Keshav
    Karmakar, Kallol Krishna
    Varadharajan, Vijay
    Tupakula, Uday
    Yu, Shui
    [J]. IEEE COMMUNICATIONS LETTERS, 2019, 23 (04) : 612 - 615
  • [2] OpenSec: Policy-Based Security Using Software-Defined Networking
    Lara, Adrian
    Ramamurthy, Byrav
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2016, 13 (01): : 30 - 42
  • [3] Policy-based Orchestration of NFV Services in Software-Defined Networks
    Giotis, K.
    Kryftis, Y.
    Maglaris, V.
    [J]. 2015 1ST IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT), 2015,
  • [4] Policy-based QoS Management Framework for Software-Defined Networks
    Al-Jawad, Ahmed
    Shah, Purav
    Gemikonakli, Orhan
    Trestian, Ramona
    [J]. 2018 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2018), 2018,
  • [5] Policy-Based Management for Green Mobile Networks Through Software-Defined Networking
    Huertas Celdran, Alberto
    Gil Perez, Manuel
    Garcia Clemente, Felix J.
    Martinez Perez, Gregorio
    [J]. MOBILE NETWORKS & APPLICATIONS, 2019, 24 (02): : 657 - 666
  • [6] Policy-Based Management for Green Mobile Networks Through Software-Defined Networking
    Alberto Huertas Celdrán
    Manuel Gil Pérez
    Félix J. García Clemente
    Gregorio Martínez Pérez
    [J]. Mobile Networks and Applications, 2019, 24 : 657 - 666
  • [7] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    [J]. 2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [8] A Policy-Based Architecture for Container Migration in Software Defined Infrastructures
    Tao, Xu
    Esposito, Flavio
    Sacco, Alessio
    Marchetto, Guido
    [J]. PROCEEDINGS OF THE 2019 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2019), 2019, : 198 - 202
  • [9] Towards an Architecture for Policy-Based Management of Software Defined Coalitions
    Williams, C.
    Bertino, E.
    Verma, D.
    Calo, S.
    Leung, K.
    Dearlove, C.
    [J]. 2017 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTED, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI), 2017,
  • [10] Software-Defined Mobile Networks Security
    Min Chen
    Yongfeng Qian
    Shiwen Mao
    Wan Tang
    Ximin Yang
    [J]. Mobile Networks and Applications, 2016, 21 : 729 - 743