A Novel Secure and Efficient Policy Management Framework for Software Defined Network

被引:7
作者
Tripathy, Bata Krishna [1 ]
Sethy, Ananta Gopal [1 ]
Bera, Padmalochan [1 ]
Rahman, Mohammad Ashiqur [2 ]
机构
[1] Indian Inst Technol Bhubaneswar, Bhubaneswar, Orissa, India
[2] Tennessee Technol Univ, Cookeville, TN USA
来源
PROCEEDINGS 2016 IEEE 40TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC), VOL 2 | 2016年
关键词
Software Defined Network; Network Control and Management Function; Controller; Policy rule; Flow table rule; Policy management;
D O I
10.1109/COMPSAC.2016.31
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Software Defined Network (SDN) paradigm provides a flexible execution platform for running different Network Control and Management Functions (NF). This provides scope for efficient management and control of traffic flows in the network. The network functions heavily rely on heterogeneous and complex network policies. These network policies can be defined by different administrators and configured (pushed to the controller) through distributed Network Application and Management Servers. Thus, efficient management and correct enforcement of network policies is an important, but a challenging problem. Our proposed policy management framework ensures, the policies are enforced by certified servers as well as focuses on detecting and resolving the potential conflicts among the heterogeneous policy rules. In addition, it maintains consistency between the flow table rules and the on-demand changes in policy rules in the application layer. Our proposed framework comprises of three novel network control functions namely, Trust Verify, Policy Conflict Resolve and Policy Consistency Check. These functions combinedly ensure security, correctness and adaptability with the dynamic on-demand changes in heterogeneous policy rules in an SDN environment. We demonstrate our framework with an extended case study of an SDN-based enterprise network.
引用
收藏
页码:423 / 430
页数:8
相关论文
共 11 条
  • [1] Ben-Itzhak Y, 2015, PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), P80, DOI 10.1109/INM.2015.7140279
  • [2] Bera P., 2011, SECURITY COMMUNICATI, V4
  • [3] Chadha R., 2008, POLICY DRIVEN MOBILE
  • [4] Ferguson AndrewD., 2012, HOTSDN, P37, DOI DOI 10.1145/2342441.2342450
  • [5] Han WY, 2014, LECT NOTES COMPUT SC, V8566, P356, DOI 10.1007/978-3-662-43936-4_23
  • [6] Software-Defined Networking: A Comprehensive Survey
    Kreutz, Diego
    Ramos, Fernando M. V.
    Verissimo, Paulo Esteves
    Rothenberg, Christian Esteve
    Azodolmolky, Siamak
    Uhlig, Steve
    [J]. PROCEEDINGS OF THE IEEE, 2015, 103 (01) : 14 - 76
  • [7] Machado CC, 2015, PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), P216, DOI 10.1109/INM.2015.7140295
  • [8] Monsanto Christopher., 2013, NSDI
  • [9] Nicolae Paladi, 2015, 1 INT WORKSH CLOUD S, P1
  • [10] Nishtha, 2014, 2014 INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND GRID COMPUTING (PDGC), P451, DOI 10.1109/PDGC.2014.7030788