FlowNAC: Flow-based Network Access Control

FlowNAC: Flow-based Network Access Control
复制标题

FlowNAC:基于流的网络访问控制

DOI:
--
复制
发表时间:
2014
期刊:
2014 Third European Workshop on Software Defined Networks
影响因子:
--
通讯作者:
E. Jacob
E. Jacob
中科院分区:
--
文献类型:
--
作者:
J. Matías;J. Garay;A. Mendiola;N. Toledo;E. Jacob

文献摘要

被引文献

相似文献

本文提出了一种基于流的网络访问控制方案FlowNAC,它允许用户根据所请求的目标服务授予访问网络的权限。每个服务都明确地定义为一组流,可以独立地请求,并且可以同时授权多个服务。在SDN原则上构建此建议有几个好处:SDN根据目标场景添加适当的粒度(细粒度或粗粒度),并灵活地将数据平面上的服务动态标识为一组流,以实施适当的策略。FlowNAC使用IEEE 802.1X的修改版本(新颖的EAPoL-in-EAPoL封装)对用户进行身份验证(不需要强制门户),并基于流的主动部署(而不是被动部署)进行服务级别访问控制。显式服务请求避免了误识别目标服务,因为通过分析流量(例如私有服务)可能会发生这种情况。该建议在具有挑战性的场景(并发身份验证和授权过程)中进行了评估,结果令人振奋。
This paper presents FlowNAC, a Flow-based Network Access Control solution that allows to grant users the rights to access the network depending on the target service requested. Each service, defined univocally as a set of flows, can be independently requested and multiple services can be authorized simultaneously. Building this proposal over SDN principles has several benefits: SDN adds the appropriate granularity (fine-or coarse-grained) depending on the target scenario and flexibility to dynamically identify the services at data plane as a set of flows to enforce the adequate policy. FlowNAC uses a modified version of IEEE 802.1X (novel EAPoL-in-EAPoL encapsulation) to authenticate the users (without the need of a captive portal) and service level access control based on proactive deployment of flows (instead of reactive). Explicit service request avoids misidentifying the target service, as it could happen by analyzing the traffic (e.g. private services). The proposal is evaluated in a challenging scenario (concurrent authentication and authorization processes) with promising results.