首页> 外文会议>IEEE Conference on Communications and Network Security >Security policy checking in distributed SDN based clouds
【24h】

Security policy checking in distributed SDN based clouds

机译:基于分布式SDN的云中的安全策略检查

获取原文

摘要

Separation of network control from devices in Software Defined Network (SDN) allows for centralized implementation and management of security policies in a cloud computing environment. The ease of programmability also makes SDN a great platform implementation of various initiatives that involve application deployment, dynamic topology changes, and decentralized network management in a multi-tenant data center environment. Dynamic change of network topology, or host reconfiguration in such networks might require corresponding changes to the flow rules in the SDN based cloud environment. Verifying adherence of these new flow policies in the environment to the organizational security policies and ensuring a conflict free environment is especially challenging. In this paper, we extend the work on rule conflicts from a traditional environment to an SDN environment, introducing a new classification to describe conflicts stemming from cross-layer conflicts. Our framework ensures that in any SDN based cloud, flow rules do not have conflicts at any layer; thereby ensuring that changes to the environment do not lead to unintended consequences. We demonstrate the correctness, feasibility and scalability of our framework through a proof-of-concept prototype.
机译:将网络控制与软件定义网络(SDN)中的设备分开,可以在云计算环境中集中实施和管理安全策略。易于编程也使SDN成为各种计划的出色平台实施,这些计划涉及在多租户数据中心环境中的应用程序部署,动态拓扑更改和分散式网络管理。网络拓扑的动态更改或此类网络中的主机重新配置可能需要对基于SDN的云环境中的流规则进行相应的更改。验证环境中这些新的流策略是否符合组织安全策略并确保无冲突的环境尤其具有挑战性。在本文中,我们将规则冲突的工作从传统环境扩展到了SDN环境,并引入了一种新的分类来描述由跨层冲突引起的冲突。我们的框架确保在任何基于SDN的云中,流规则在任何层都不会发生冲突。从而确保环境变化不会导致意想不到的后果。我们通过概念验证原型展示了我们框架的正确性,可行性和可扩展性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号