Brew: A Security Policy Analysis Framework for Distributed SDN-Based Cloud Environments

Brew: A Security Policy Analysis Framework for Distributed SDN-Based Cloud Environments
复制标题

DOI:
10.1109/tdsc.2017.2726066
复制
发表时间:
2019-11
影响因子:
7.3
通讯作者:
Sandeep Pisharody;Janakarajan Natarajan;Ankur Chowdhary;Abdullah Alshalan;Dijiang Huang
Sandeep Pisharody;Janakarajan Natarajan;Ankur Chowdhary;Abdullah Alshalan;Dijiang Huang
中科院分区:
计算机科学2区
文献类型:
--
作者:
Sandeep Pisharody;Janakarajan Natarajan;Ankur Chowdhary;Abdullah Alshalan;Dijiang Huang

文献摘要

被引文献

相似文献

软件定义网络(SDN)的易编程性使其成为多租户数据中心环境中涉及应用程序部署、动态拓扑变化和分散式网络管理的各种计划的绝佳平台实施。然而,在这样的环境中实现安全解决方案充满了策略冲突和一致性问题,该问题的难度受到SDN控制器的分布方案的影响。在本文中,我们提出了Brew,一个安全策略分析框架上实现的OpenDaylight SDN控制器,具有全面的冲突检测和解决模块,以确保没有两个流规则在基于SDN的分布式云环境中的任何一层发生冲突,从而确保一致的无冲突的安全策略实施,防止信息泄漏。我们提出了在分散环境中的流规则的全局优先级的技术,通过识别和分类跨层冲突产生的冲突,将防火墙规则冲突分类从传统环境扩展到SDN流规则冲突,并提供这些冲突的独立解决策略。或者,如果需要管理员输入来解决冲突,则实现新颖的可视化方案以帮助管理员以图形方式查看冲突。我们证明了我们的框架的正确性,可行性和可扩展性,通过一个概念验证原型。
The ease of programmability in Software-Defined Networking (SDN) makes it a great platform implementation of various initiatives that involve application deployment, dynamic topology changes, and decentralized network management in a multi-tenant data center environment. However, implementing security solutions in such an environment is fraught with policy conflicts and consistency issues with the hardness of this problem being affected by the distribution scheme for the SDN controllers. In this paper we present Brew, a security policy analysis framework implemented on an OpenDaylight SDN controller, that has comprehensive conflict detection and resolution modules to ensure that no two flow rules in a distributed SDN-based cloud environment have conflicts at any layer; thereby assuring consistent conflict-free security policy implementation and preventing information leakage. We present techniques for global prioritization of flow rules in a decentralized environment, extend firewall rule conflict classification from a traditional environment to SDN flow rule conflicts by recognizing and classifying conflicts stemming from cross-layer conflicts and provide strategies for unassisted resolution of these conflicts. Alternately, if administrator input is desired to resolve conflicts, a novel visualization scheme is implemented to help the administrators view the conflicts graphically. We demonstrate the correctness, feasibility and scalability of our framework through a proof-of-concept prototype.