An End-Host-Importance-Aware Secure Service-Enabled Hybrid SDN Deployment

被引:2
作者
Feng, Wendi [1 ]
Liu, Chuanchang [2 ]
Cheng, Bo [2 ]
Chen, Junliang [2 ]
Wan, Zhiguo [3 ]
机构
[1] Beijing Informat Sci & Technol Univ, Sch Comp Sci, Beijing 100192, Peoples R China
[2] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
[3] Zhejiang Lab, Hangzhou 311122, Peoples R China
来源
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT | 2023年 / 20卷 / 02期
基金
北京市自然科学基金; 中国国家自然科学基金;
关键词
Hybrid SDN; network security; network deployment; end-host importance aware;
D O I
10.1109/TNSM.2022.3208695
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security is critical to networks, but TCP/IP-based legacy networks are difficult to advance new security functions due to the use of costly inflexible hardware devices and error-prone network configurations. Recent literature explores the paradigm of consolidating security services with the forwarding functionality using Software-defined Networking (SDN). Existing full SDN deployment, replacing all legacy network devices with SDN devices, is cost-prohibitive. Whereas the hybrid SDN that only upgrades partial legacy devices to SDN switches is considered practical. However, the challenge is to minimize threats and deployment expenses simultaneously under heterogeneous end-host businesses that have various importance. In this paper, we study the challenge and propose the End-host-importance-Aware secure service-enabled hybrid Sdn deplOymeNt (EASON) problem. We mathematically formulate the EASON problem as an integer programming problem, prove its non-polynomial time complexity, and propose a heuristic algorithm called BonSec. We conduct rigorous simulations on real-world topologies and traces. Experimental results show that BonSec achieves comparable security and cost performances to the optimal solution on small topologies. Meanwhile, it is scalable on larger topologies.
引用
收藏
页码:2056 / 2070
页数:15
相关论文
共 83 条
[1]  
AlSabeh A., 2022, PROC NETW DISTRIB SY, P1
[2]   Hybrid SDN Networks: A Survey of Existing Approaches [J].
Amin, Rashid ;
Reisslein, Martin ;
Shah, Nadir .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (04) :3259-3306
[3]  
[Anonymous], 2022, ROUTER SECURITY
[4]  
[Anonymous], 2002, THESIS
[5]  
[Anonymous], 2022, ABILENE NETWORK TOPO
[6]  
[Anonymous], 2022, Gurobi Optimizer
[7]  
[Anonymous], 2003, P 35 ANN ACM S THEOR
[8]  
[Anonymous], 2022, GEANT LOOKING GLASS
[9]  
[Anonymous], 2022, PYPLOT SCALES
[10]  
[Anonymous], 2022, HUAWEI NETENGINE AR6