Anomaly-Free Policy Composition in Software-Defined Networks

被引:0
|
作者
Rezvani, Mohsen [1 ]
Ignjatovic, Aleksandar [1 ]
Pagnucco, Maurice [1 ]
Jha, Sanjay [1 ]
机构
[1] UNSW Australia, Sch Comp Sci & Engn, Sydney, NSW, Australia
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Software Defined Networking (SDN) provides considerable simplification of design and deployment of various network applications for large networks. Each application has its own view of network policy and sends its policy to a network hypervisor in which a composed policy is generated from the application policies and deployed into the data plane. A significant challenge for the hypervisor is to detect and resolve both intra and inter policy anomalies during the policy composition. However, current SDN compilers do not consider the policy anomalies well and generate large number of unnecessary rules for the data plane. This leads to a considerable inefficiency in both policy composition and policy deployment. In this paper, we propose a novel framework for policy composition in a SDN hypervisor which takes into account both inter and intra policy anomalies. Moreover, we augment the framework with an efficient insertion transformation mechanism which allows the applications to issue rule insertion and priority change updates. Our evaluation shows that our method is several orders of magnitude more efficient than the state of the art in both policy composition and compiling the rule insertion updates.
引用
收藏
页码:28 / 36
页数:9
相关论文
共 50 条
  • [1] Efficient Forwarding Anomaly Detection in Software-Defined Networks
    Li, Qi
    Liu, Yunpeng
    Liu, Zhuotao
    Zhang, Peng
    Pang, Chunhui
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2021, 32 (11) : 2676 - 2690
  • [2] FADE: Detecting Forwarding Anomaly in Software-Defined Networks
    Pang, Chunhui
    Jiang, Yong
    Li, Qi
    2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,
  • [3] Policy and Resource Orchestration in Software-Defined Networks
    Wang, Anduo
    Wu, Jie
    2018 4TH IEEE INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC 2018), 2018, : 203 - 206
  • [4] Athena: A Framework for Scalable Anomaly Detection in Software-Defined Networks
    Lee, Seunghyeon
    Kim, Jinwoo
    Shin, Seungwon
    Porras, Phillip
    Yegneswaran, Vinod
    2017 47TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2017, : 249 - 260
  • [5] Comprehensive Analysis of DDoS Anomaly Detection in Software-Defined Networks
    Hirsi, Abdinasir
    Alhartomi, Mohammed A.
    Audah, Lukman
    Salh, Adeb
    Sahar, Nan Mad
    Ahmed, Salman
    Ansa, Godwin Okon
    Farah, Abdullahi
    IEEE ACCESS, 2025, 13 : 23013 - 23071
  • [6] LPM: Layered Policy Management for Software-Defined Networks
    Han, Wonkyu
    Hu, Hongxin
    Ahn, Gail-Joon
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXVIII, 2014, 8566 : 356 - 363
  • [7] A Framework for Policy Inconsistency Detection in Software-Defined Networks
    Lee, Seungsoo
    Woo, Seungwon
    Kim, Jinwoo
    Nam, Jaehyun
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (03) : 1410 - 1423
  • [8] LOADS: Load Optimization and Anomaly Detection Scheme for Software-Defined Networks
    Chaudhary, Rajat
    Kumar, Neeraj
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2019, 68 (12) : 12329 - 12344
  • [9] Generative Adversarial Network Models for Anomaly Detection in Software-Defined Networks
    Zacaron, Alexandro Marcelo
    Lent, Daniel Matheus Brandao
    da Silva Ruffo, Vitor Gabriel
    Carvalho, Luiz Fernando
    Proenca Jr, Mario Lemes
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2024, 32 (04)
  • [10] Anomaly Detection in Software-Defined Networks Using Cross-Validation
    Krzemien, W.
    Jedrasiak, K.
    Nawrat, A.
    Daniec, K.
    INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER AND ENERGY TECHNOLOGIES (ICECET 2021), 2021, : 250 - 256