Intent-Driven Security Policy Management for Software-Defined Systems

被引:6
|
作者
Chowdhary, Ankur [1 ]
Sabur, Abdulhakim [1 ,2 ]
Vadnere, Neha [1 ]
Huang, Dijiang [1 ]
机构
[1] Arizona State Univ, Sch Comp & Augmented Intelligence, Tempe, AZ 85287 USA
[2] Taibah Univ, Dept Comp Engn & Coll Comp Sci & Engn, Madinah 42353, Saudi Arabia
基金
美国国家科学基金会;
关键词
Security; Electronics packaging; Complexity theory; Service function chaining; Routing; Scalability; Model checking; Software-defined networks (SDN); bounded model checking (BMC); security policy management; network invariant checking; service function chaining; VERIFICATION;
D O I
10.1109/TNSM.2022.3183591
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Different network controllers are utilized in a multi-domain software-defined systems (SDx) to manage the networking resources. However, these controllers operate using a different high-level language (intent). Thus, the admin needs to perform cross-layer translation from the user requirements to the underlying network controller format, increasing human-in-the-loop overhead. There are two primary security and management challenges involved in managing multi-domain controllers. The first challenge is how to design an SDN controller language that can effectively convert human-specified networking policies at the control plane into the network flow rules level at the data plane. The second challenge is how to reduce the complexity of network flow rules conflict checking at the data plane. To address these challenges, we present a new intent-based security policy enforcement solution called INTPOL. First, INTPOL provides a unified intent rules that abstracts the network admin from the underlying network controller's format. Second, INTPOL develops a networking service solution to use a bounded formal model for network service compliance checking that significantly reduces the complexity of flow rules conflicts checking at the data plane level. Finally, INTPOL is expendable from a single SDN domain to multiple SDN domains and hybrid networks by applying network service function chaining (SFC) for inter-domain policy management.
引用
收藏
页码:5208 / 5223
页数:16
相关论文
共 50 条
  • [21] Intent-based service management for heterogeneous software-defined infrastructure domains
    Davoli, Gianluca
    Cerroni, Walter
    Tomovic, Slavica
    Buratti, Chiara
    Contoli, Chiara
    Callegati, Franco
    [J]. INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2019, 29 (01)
  • [22] Software-Defined Networking for Improving Security in Smart Grid Systems
    Demirci, Sedef
    Sagiroglu, Seref
    [J]. 2018 7TH INTERNATIONAL CONFERENCE ON RENEWABLE ENERGY RESEARCH AND APPLICATIONS (ICRERA), 2018, : 1021 - 1026
  • [23] OpenSec: Policy-Based Security Using Software-Defined Networking
    Lara, Adrian
    Ramamurthy, Byrav
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2016, 13 (01): : 30 - 42
  • [24] Software-Defined Mobile Networks Security
    Min Chen
    Yongfeng Qian
    Shiwen Mao
    Wan Tang
    Ximin Yang
    [J]. Mobile Networks and Applications, 2016, 21 : 729 - 743
  • [25] Orchestration of Software-Defined Security Services
    Luo, Song
    Ben Salem, Malek
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC), 2016, : 436 - 441
  • [26] Software-Defined Mobile Networks Security
    Chen, Min
    Qian, Yongfeng
    Mao, Shiwen
    Tang, Wan
    Yang, Ximin
    [J]. MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 729 - 743
  • [27] Security Analysis of a Software-Defined Radar
    Yerkes, Blake
    Ramsey, Benjamin
    Rice, Mason
    Pecarina, John
    Dunlap, Stephen
    [J]. PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2017), 2017, : 386 - 395
  • [28] On Security in Software-Defined Vehicular Cloud
    Kim, Myeongsu
    Jang, Insun
    Choo, Sukjin
    Pack, Sangheon
    [J]. 2016 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC 2016): TOWARDS SMARTER HYPER-CONNECTED WORLD, 2016, : 1259 - 1260
  • [29] Intent-Driven Composition of Resource-Management SDN Applications
    Heorhiadi, Victor
    Chandrasekaran, Sanjay
    Reiter, Michael K.
    Sekar, Vyas
    [J]. CONEXT'18: PROCEEDINGS OF THE 14TH INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES, 2018, : 86 - 97
  • [30] Software-Defined BusinessImplications for IT Management
    Rainer Alt
    Jan Marco Leimeister
    Thomas Priemuth
    Stephan Sachse
    Nils Urbach
    Nico Wunderlich
    [J]. Business & Information Systems Engineering, 2020, 62 : 609 - 621