首页> 外文会议>IEEE Conference on Computer Communications >AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined Networks
【24h】

AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined Networks

机译:AudiSDN:在软件定义的网络中自动检测网络策略不一致

获取原文

摘要

At the foundation of every network security architecture lies the premise that formulated network flow policies are reliably deployed and enforced by the network infrastructure. However, software-defined networks (SDNs) add a particular challenge to satisfying this premise, as for SDNs the flow pol-icy implementation spans multiple applications and abstraction layers across the SDN stack. In this paper, we focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among these components. This question is rather essential, as when such inconsistencies arise the implications to the security and reliability of the network are devastating. We present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise in OpenFlow networks, the most prevalent SDN protocol used today. We also present results from applying AudiSDN to two widely used SDN controllers, Floodlight and ONOS. In fact, our test results have led to the filing of 3 separate CVE reports. We believe that the approach presented in this paper is applicable to the breadth of OpenFlow platforms used today, and that its broader usage will help to address a serious but yet understudied pragmatic concern.
机译:每种网络安全体系结构的基础都在于,已制定的网络流量策略可以由网络基础结构可靠地部署和实施的前提。但是,软件定义网络(SDN)满足这一前提提出了一个特殊的挑战,因为对于SDN,流策略实现跨越了SDN堆栈中的多个应用程序和抽象层。在本文中,我们关注于如何自动识别SDN堆栈无法防止这些组件之间出现策略不一致的情况的问题。这个问题非常重要,因为当出现这种不一致时,对网络安全性和可靠性的影响将是毁灭性的。我们介绍了AudiSDN,这是一个自动的模糊测试框架,旨在设计测试用例,在这些用例中,OpenFlow网络(当今使用最广泛的SDN协议)中可能会出现策略不一致的情况。我们还将介绍将AudiSDN应用于两个广泛使用的SDN控制器(Floodlight和ONOS)的结果。实际上,我们的测试结果导致提交了3个单独的CVE报告。我们认为,本文介绍的方法适用于当今使用的OpenFlow平台的广泛性,并且其更广泛的使用将有助于解决严重但尚未被研究的实用问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号