Automated Verification of Security Chains in Software-Defined Networks with Synaptic

被引:0
|
作者
Schnepf, Nicolas [1 ]
Badonnel, Remi [1 ]
Lahmadi, Abdelkader [1 ]
Merz, Stephan [1 ]
机构
[1] Univ Lorraine, CNRS, INRIA, Loria, Campus Sci, Nancy, France
关键词
Security Management; Software-Defined Networking; Formal Verification;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networks provide new facilities for deploying security mechanisms dynamically. In particular, it is possible to build and adjust security chains to protect the infrastructures, by combining different security functions, such as firewalls, intrusion detection systems and services for preventing data leakage. It is important to ensure that these security chains, in view of their complexity and dynamics, are consistent and do not include security violations. We propose in this paper an automated strategy for supporting the verification of security chains in software-defined networks. It relies on an architecture integrating formal verification methods for checking both the control and data planes of these chains, before their deployment. We describe algorithms for translating specifications of security chains into formal models that can then be verified by SMT1 solving or model checking. Our solution is prototyped as a package, named Synaptic, built as an extension of the Frenetic family of SDN programming languages. The performances of our approach are evaluated through extensive experimentations based on the CVC4, veriT, and nuXmv checkers.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Automated Factorization of Security Chains in Software-Defined Networks
    Schnepf, Nicolas
    Badonnel, Remi
    Lahmadi, Abdelkader
    Merz, Stephan
    2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019, : 374 - 380
  • [2] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [3] Software-Defined Mobile Networks Security
    Min Chen
    Yongfeng Qian
    Shiwen Mao
    Wan Tang
    Ximin Yang
    Mobile Networks and Applications, 2016, 21 : 729 - 743
  • [4] Security Evaluation in Software-Defined Networks
    Ivkic, Igor
    Thiede, Dominik
    Race, Nicholas
    Broadbent, Matthew
    Gouglidis, Antonios
    CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2022, CLOSER 2023, 2024, 1845 : 66 - 91
  • [5] Software-Defined Mobile Networks Security
    Chen, Min
    Qian, Yongfeng
    Mao, Shiwen
    Tang, Wan
    Yang, Ximin
    MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 729 - 743
  • [6] Analytics-Enhanced Automated Code Verification for Dependability of Software-Defined Networks
    Jagadeesan, Lalita J.
    Mendiratta, Veena
    2017 IEEE 28TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW 2017), 2017, : 139 - 145
  • [7] Automated Bug Removal for Software-Defined Networks
    Wu, Yang
    Chen, Ang
    Haeberlen, Andreas
    Zhou, Wenchao
    Loo, Boon Thau
    PROCEEDINGS OF NSDI '17: 14TH USENIX SYMPOSIUM ON NETWORKED SYSTEMS DESIGN AND IMPLEMENTATION, 2017, : 719 - 733
  • [8] Improving the Routing Security in Software-Defined Networks
    Ai, Jianjian
    Guo, Zehua
    Chen, Hongchang
    Cheng, Guozhen
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (05) : 838 - 841
  • [9] Semantic Security Tools in Software-Defined Networks
    Antoshina, E. Ju.
    Chalyy, D. Ju.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2018, 52 (07) : 605 - 607
  • [10] Formal modeling and verification of software-defined networks: A survey
    Shukla, Nitin
    Pandey, Mayank
    Srivastava, Shashank
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2019, 29 (05)