Auto-Configuration of ACL Policy in Case of Topology Change in Hybrid SDN

被引:19
作者
Amin, Rashid [1 ,2 ]
Shah, Nadir [1 ]
Shah, Babar [3 ]
Alfandi, Omar [3 ]
机构
[1] COMSATS Inst Informat Technol, Wah Cantt 47040, Pakistan
[2] Univ Engn & Technol, Taxila 47040, Pakistan
[3] Zayed Univ, Abu Dhabi 144534, U Arab Emirates
关键词
Topology change; policy configuration; tree; graph difference; communication switching;
D O I
10.1109/ACCESS.2016.2641482
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has emerged as a new network architecture, which decouples both the control and management planes from data plane at forwarding devices. However, SDN deployment is not widely adopted due to the budget constraints of organizations. This is because organizations are always reluctant to invest too much budget to establish a new network infrastructure from scratch. One feasible solution is to deploy a limited number of SDN-enabled devices along with traditional (legacy) network devices in the network of an organization by incrementally replacing traditional network by SDN, which is called hybrid SDN (Hybrid SDN) architecture. Network management and control in Hybrid SDN are vital tasks that require significant effort and resources. Manual handling of these tasks is error prone. Whenever network topology changes, network policies (e.g., access control list) configured at the interfaces of forwarding devices (switches/routers) may be violated. That creates severe security threats for the whole network and degrades the network performance. In this paper, we propose a new approach for Hybrid SDN that auto-detects the interfaces of forwarding devices and network policies that are affected due to change in network topology. In the proposed approach, we model network-wide policy and local policy at forwarding device using a three-tuple and a six-tuple, respectively. We compute graph to represent the topology of the network. By using graph difference technique, we detect a possible change in topology. In the case of topology change, we verify policy for updated topology by traversing tree using six-tuple. If there is any violation in policy implementation, then affected interfaces are indicated and policies that need to be configured are also indicated. Then, policies are configured on the updated topology according to specification in an improved way. Simulation results show that our proposed approach enhances the network efficiency in term of successful packet delivery ratio, the ratio of packets that violated the policy and normalized overhead.
引用
收藏
页码:9437 / 9450
页数:14
相关论文
共 28 条
[1]   Graph based anomaly detection and description: a survey [J].
Akoglu, Leman ;
Tong, Hanghang ;
Koutra, Danai .
DATA MINING AND KNOWLEDGE DISCOVERY, 2015, 29 (03) :626-688
[2]  
[Anonymous], P IND TRACK 13 ACM I
[3]  
[Anonymous], 2015, PROC 1 ACM SIGCOMM S
[4]   GRAPH SPECTRAL TECHNIQUES IN COMPUTER SCIENCES [J].
Arsic, Branko ;
Cvetkovic, Dragos ;
Simic, Slobodan K. ;
Skaric, Milan .
APPLICABLE ANALYSIS AND DISCRETE MATHEMATICS, 2012, 6 (01) :1-30
[5]   Rethinking Enterprise Network Control [J].
Casado, Martin ;
Freedman, Michael J. ;
Pettit, Justin ;
Luo, Jianying ;
Gude, Natasha ;
McKeown, Nick ;
Shenker, Scott .
IEEE-ACM TRANSACTIONS ON NETWORKING, 2009, 17 (04) :1270-1283
[6]   Incremental Graph Pattern Matching [J].
Fan, Wenfei ;
Wang, Xin ;
Wu, Yinghui .
ACM TRANSACTIONS ON DATABASE SYSTEMS, 2013, 38 (03)
[7]  
Gai S., 2000, U.S. Patent, Patent No. [6 167 445, 6167445]
[8]   Routing in a highly dynamic topology [J].
Ganjali, Y ;
McKeown, N .
2005 SECOND ANNUAL IEEE COMMUNICATIONS SOCIETY CONFERENCE ON SENSOR AND AD HOC COMMUNICATIONS AND NETWORKS, 2005, :164-175
[9]   Survey of Important Issues in UAV Communication Networks [J].
Gupta, Lav ;
Jain, Raj ;
Vaszkun, Gabor .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2016, 18 (02) :1123-1152
[10]   Network Function Virtualization: Challenges and Opportunities for Innovations [J].
Han, Bo ;
Gopalakrishnan, Vijay ;
Ji, Lusheng ;
Lee, Seungjoon .
IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (02) :90-97