Anomaly-Free Policy Composition in Software-Defined Networks

被引:0
|
作者
Rezvani, Mohsen [1 ]
Ignjatovic, Aleksandar [1 ]
Pagnucco, Maurice [1 ]
Jha, Sanjay [1 ]
机构
[1] UNSW Australia, Sch Comp Sci & Engn, Sydney, NSW, Australia
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Software Defined Networking (SDN) provides considerable simplification of design and deployment of various network applications for large networks. Each application has its own view of network policy and sends its policy to a network hypervisor in which a composed policy is generated from the application policies and deployed into the data plane. A significant challenge for the hypervisor is to detect and resolve both intra and inter policy anomalies during the policy composition. However, current SDN compilers do not consider the policy anomalies well and generate large number of unnecessary rules for the data plane. This leads to a considerable inefficiency in both policy composition and policy deployment. In this paper, we propose a novel framework for policy composition in a SDN hypervisor which takes into account both inter and intra policy anomalies. Moreover, we augment the framework with an efficient insertion transformation mechanism which allows the applications to issue rule insertion and priority change updates. Our evaluation shows that our method is several orders of magnitude more efficient than the state of the art in both policy composition and compiling the rule insertion updates.
引用
收藏
页码:28 / 36
页数:9
相关论文
共 50 条
  • [1] FADE: Detecting Forwarding Anomaly in Software-Defined Networks
    Pang, Chunhui
    Jiang, Yong
    Li, Qi
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,
  • [2] Efficient Forwarding Anomaly Detection in Software-Defined Networks
    Li, Qi
    Liu, Yunpeng
    Liu, Zhuotao
    Zhang, Peng
    Pang, Chunhui
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2021, 32 (11) : 2676 - 2690
  • [3] Policy and Resource Orchestration in Software-Defined Networks
    Wang, Anduo
    Wu, Jie
    [J]. 2018 4TH IEEE INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC 2018), 2018, : 203 - 206
  • [4] Athena: A Framework for Scalable Anomaly Detection in Software-Defined Networks
    Lee, Seunghyeon
    Kim, Jinwoo
    Shin, Seungwon
    Porras, Phillip
    Yegneswaran, Vinod
    [J]. 2017 47TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2017, : 249 - 260
  • [5] LPM: Layered Policy Management for Software-Defined Networks
    Han, Wonkyu
    Hu, Hongxin
    Ahn, Gail-Joon
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXVIII, 2014, 8566 : 356 - 363
  • [6] A Framework for Policy Inconsistency Detection in Software-Defined Networks
    Lee, Seungsoo
    Woo, Seungwon
    Kim, Jinwoo
    Nam, Jaehyun
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (03) : 1410 - 1423
  • [7] Generative Adversarial Network Models for Anomaly Detection in Software-Defined Networks
    Zacaron, Alexandro Marcelo
    Lent, Daniel Matheus Brandao
    da Silva Ruffo, Vitor Gabriel
    Carvalho, Luiz Fernando
    Proenca Jr, Mario Lemes
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2024, 32 (04)
  • [8] LOADS: Load Optimization and Anomaly Detection Scheme for Software-Defined Networks
    Chaudhary, Rajat
    Kumar, Neeraj
    [J]. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2019, 68 (12) : 12329 - 12344
  • [9] Anomaly Detection in Software-Defined Networks Using Cross-Validation
    Krzemien, W.
    Jedrasiak, K.
    Nawrat, A.
    Daniec, K.
    [J]. INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER AND ENERGY TECHNOLOGIES (ICECET 2021), 2021, : 250 - 256
  • [10] The Devil is in the Details: Confident & Explainable Anomaly Detector for Software-Defined Networks
    Das, Tapadhir
    Shukla, Raj Mani
    Sengupta, Shamik
    [J]. 2021 IEEE 20TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2021,