Intent-Driven Security Policy Management for Software-Defined Systems

被引:6
|
作者
Chowdhary, Ankur [1 ]
Sabur, Abdulhakim [1 ,2 ]
Vadnere, Neha [1 ]
Huang, Dijiang [1 ]
机构
[1] Arizona State Univ, Sch Comp & Augmented Intelligence, Tempe, AZ 85287 USA
[2] Taibah Univ, Dept Comp Engn & Coll Comp Sci & Engn, Madinah 42353, Saudi Arabia
基金
美国国家科学基金会;
关键词
Security; Electronics packaging; Complexity theory; Service function chaining; Routing; Scalability; Model checking; Software-defined networks (SDN); bounded model checking (BMC); security policy management; network invariant checking; service function chaining; VERIFICATION;
D O I
10.1109/TNSM.2022.3183591
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Different network controllers are utilized in a multi-domain software-defined systems (SDx) to manage the networking resources. However, these controllers operate using a different high-level language (intent). Thus, the admin needs to perform cross-layer translation from the user requirements to the underlying network controller format, increasing human-in-the-loop overhead. There are two primary security and management challenges involved in managing multi-domain controllers. The first challenge is how to design an SDN controller language that can effectively convert human-specified networking policies at the control plane into the network flow rules level at the data plane. The second challenge is how to reduce the complexity of network flow rules conflict checking at the data plane. To address these challenges, we present a new intent-based security policy enforcement solution called INTPOL. First, INTPOL provides a unified intent rules that abstracts the network admin from the underlying network controller's format. Second, INTPOL develops a networking service solution to use a bounded formal model for network service compliance checking that significantly reduces the complexity of flow rules conflicts checking at the data plane level. Finally, INTPOL is expendable from a single SDN domain to multiple SDN domains and hybrid networks by applying network service function chaining (SFC) for inter-domain policy management.
引用
收藏
页码:5208 / 5223
页数:16
相关论文
共 50 条
  • [1] IS2N: Intent-Driven Security Software-Defined Network With Blockchain
    Song, Yanbo
    Feng, Tao
    Yang, Chungang
    Mi, Xinru
    Jiang, Shanqing
    Guizani, Mohsen
    [J]. IEEE NETWORK, 2024, 38 (03): : 118 - 127
  • [2] OSWireless: Enhancing Automation for Optimizing Intent-Driven Software-Defined Wireless Networks
    Moorthy, Sabarish Krishna
    Guan, Zhangyu
    Mastronarde, Nicholas
    Bentley, Elizabeth Serena
    Medley, Michael
    [J]. 2022 IEEE 19TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2022), 2022, : 202 - 210
  • [3] MD-IDN: Multi-Domain Intent-Driven Networking in Software-Defined Infrastructures
    Arezoumand, Saeed
    Dzeparoska, Kristina
    Bannazadeh, Hadi
    Leon-Garcia, Alberto
    [J]. 2017 13TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2017,
  • [4] A Behavior-Driven Approach to Intent Specification for Software-Defined Infrastructure Management
    Esposito, Flavio
    Wang, Jiayi
    Contoli, Chiara
    Davoli, Gianluca
    Cerroni, Walter
    Callegati, Franco
    [J]. 2018 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2018,
  • [5] Intent-Based Management for Software-Defined Vehicles in Intelligent Transportation Systems
    Shen, Yiwen
    Ahn, Yoseop
    Gu, Mose
    Jeong, Jaehoon
    [J]. 2024 IEEE 10TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION, NETSOFT 2024, 2024, : 1 - 6
  • [6] Intent Negotiation Framework for Intent-Driven Service Management
    Sharma, Yogesh
    Bhamare, Deval
    Kassler, Andreas
    Taheri, Javid
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2023, 61 (06) : 73 - 79
  • [7] SMART Intent-Driven Network Management
    Yang, Chungang
    Mi, Xinru
    Ouyang, Ying
    Dong, Ru
    Guo, Junjie
    Guizani, Mohsen
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2023, 61 (01) : 106 - 112
  • [8] Analysis of Policy-Based Security Management System in Software-Defined Networks
    Sood, Keshav
    Karmakar, Kallol Krishna
    Varadharajan, Vijay
    Tupakula, Uday
    Yu, Shui
    [J]. IEEE COMMUNICATIONS LETTERS, 2019, 23 (04) : 612 - 615
  • [9] Leveraging software-defined networking for security policy enforcement
    Liu, Jiaqiang
    Li, Yong
    Wang, Huandong
    Jin, Depeng
    Su, Li
    Zeng, Lieguang
    Vasilakos, Thanos
    [J]. INFORMATION SCIENCES, 2016, 327 : 288 - 299
  • [10] Policy Authoring for Software-Defined Networking Management
    Machado, Cristian Cleder
    Wickboldt, Juliano Araujo
    Granville, Lisandro Zambenedetti
    Schaeffer-Filho, Alberto
    [J]. PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 216 - 224