首页> 外文会议>IEEE Global Communications Conference >OpenSec: A framework for implementing security policies using OpenFlow
【24h】

OpenSec: A framework for implementing security policies using OpenFlow

机译:OpenSec:使用OpenFlow实施安全策略的框架

获取原文

摘要

As the popularity of software defined networks (SDN) and OpenFlow increases, policy-driven network management has received more attention. Manual configuration of multiple devices is being replaced by an automated approach where a software-based, network-aware controller handles the configuration of all network devices. Software applications running on top of the network controller provide an abstraction of the topology and facilitate the task of operating the network. We propose OpenSec, an OpenFlow-based security framework that allows a network security operator to create and implement security policies written in human-readable language. Using OpenSec, the user can describe a flow in terms of OpenFlow matching fields, define which security services must be applied to that flow (deep packet inspection, intrusion detection, spam detection, etc) and specify security levels that define how OpenSec reacts if malicious traffic is detected. We implement OpenSec in the GENI testbed to evaluate the flexibility, accuracy and scalability of the framework. The experimental setup includes deep packet inspection, intrusion detection and network quarantining to secure a web server from network scanners. We achieve a constant delay when reacting to security alerts and a detection rate of 98%.
机译:随着软件定义网络(SDN)和OpenFlow的普及,策略驱动的网络管理受到了越来越多的关注。多个设备的手动配置已被自动化方法所取代,该自动化方法中基于软件的,可识别网络的控制器处理所有网络设备的配置。运行在网络控制器顶部的软件应用程序提供了拓扑的抽象,并简化了网络操作的任务。我们提出了OpenSec,这是一个基于OpenFlow的安全框架,允许网络安全运营商创建和实施以人类可读语言编写的安全策略。使用OpenSec,用户可以按照OpenFlow匹配字段描述流,定义必须对该流应用哪些安全服务(深度数据包检查,入侵检测,垃圾邮件检测等),并指定安全级别,以定义OpenSec在恶意时如何反应检测到流量。我们在GENI测试平台中实施OpenSec,以评估框架的灵活性,准确性和可扩展性。实验设置包括深度数据包检查,入侵检测和网络隔离,以确保网络服务器不受网络扫描仪的影响。当我们对安全警报做出反应时,我们获得了恒定的延迟,检测率达到了98%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号