LPM: Layered Policy Management for Software-Defined Networks

被引:0
作者
Han, Wonkyu [1 ]
Hu, Hongxin [2 ]
Ahn, Gail-Joon [1 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
[2] Clemson Univ, Clemson, SC 29634 USA
来源
DATA AND APPLICATIONS SECURITY AND PRIVACY XXVIII | 2014年 / 8566卷
关键词
Policy Management; Software-Defined Networking; Security;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking (SDN) as an emerging paradigm in networking divides the network architecture into three distinct layers such as application, control, and data layers. The multi-layered network architecture in SDN tremendously helps manage and control network traffic flows but each layer heavily relies on complex network policies. Managing and enforcing these network policies require dedicated cautions since combining multiple network modules in an SDN application not only becomes a non-trivial job, but also requires considerable efforts to identify dependencies within a module and between modules. In addition, multi-tenant SDN applications make network management tasks more difficult since there may exist unexpected interferences between traffic flows. In order to accommodate such complex network dynamics in SDN, we propose a novel policy management framework for SDN, called layered policy management (LPM). We also articulate challenges for each layer in terms of policy management and describe appropriate resolution strategies. In addition, we present a proof-of-concept implementation and demonstrate the feasibility of our approach with an SDN-based simulated network.
引用
收藏
页码:356 / 363
页数:8
相关论文
共 9 条
[1]  
[Anonymous], 2013, 20 ANN NETWORK DISTR
[2]  
Bandara AK, 2003, IEEE 4TH INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, P26
[3]  
Bonatti P., 2002, ACM Transactions on Information and Systems Security, V5, P1, DOI 10.1145/504909.504910
[4]  
Fayazbakhsh S.K., 2014, NSDI
[5]   Detecting and Resolving Firewall Policy Anomalies [J].
Hu, Hongxin ;
Ahn, Gail-Joon ;
Kulkarni, Ketan .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2012, 9 (03) :318-331
[6]  
Monsanto Christopher., 2013, NSDI
[7]  
ONF Market Education Committee, 2012, SOFTW DEF NETW NEW N
[8]  
Porras P., 2012, Proceedings of the first workshop on Hot topics in software defined networks, ACM, P121, DOI [10.1145/2342441.2342466, DOI 10.1145/2342441.2342466]
[9]  
Stephens B., 2012, P 8 INT C EMERGING N, P49, DOI DOI 10.1145/2413176.2413183