SDNSOC: Object Oriented SDN Framework

SDNSOC: Object Oriented SDN Framework
复制标题

SDNSOC:面向对象的SDN框架

DOI:
10.1145/3309194.3309196
复制
发表时间:
2019
期刊:
SDN-NFVSec '19: Proceedings of the ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization
影响因子:
--
通讯作者:
Velazquez, Alexander
Velazquez, Alexander
中科院分区:
--
文献类型:
--
作者:
Chowdhary, Ankur;Huang, Dijiang;Ahn, Gail-Joon;Kang, Myong;Kim, Anya;Velazquez, Alexander

文献摘要

参考文献

被引文献

相似文献

由SDN管理的云网络可能具有多层策略和规则冲突。应用平面可能具有冲突的用户定义的策略,并且基础设施层可能具有彼此冲突的OpenFlow规则。没有可扩展的自动编程框架来检测和解决基于SDN的云网络中的多层冲突。我们提出了一个面向对象的编程框架- SDN安全操作中心(SDNSOC),它处理在应用平面的策略组合,流规则冲突检测和解决在控制平面。我们遵循面向对象的设计原则,如代码重用,方法抽象,聚合的SDNSOC上的多租户云网络的实现。使用这种方法获得的主要好处是:(i)网络管理员从复杂的实现细节的SFC抽象。不同的网络功能的端到端的策略组合是由一个面向对象的框架,以自动化的方式处理。与最接近的竞争对手SICS和PGA相比,我们在SFC组成方面实现了37%的延迟降低。(ii)现有流量规则和传入流量之间的策略冲突检测由SDNSOC以可扩展的方式处理。该解决方案可在大型云网络上良好扩展。与Brew和Flowguard等同类作品相比,在云网络上使用100 k OpenFlow规则的安全策略冲突检测速度提高了18%。
The cloud networks managed by SDN can have multi-tier policy and rule conflicts. The application plane can have conflicting user-defined policies, and the infrastructure layer can have OpenFlow rules conflicting with each other. There is no scalable, and, automated programming framework to detect and resolve multi-tier conflicts in SDN-based cloud networks. We present an object-oriented programming framework - SDN Security Operation Center (SDNSOC), which handles policy composition at application plane, flow rule conflict detection and resolution at the control plane. We follow the design principles of object-oriented paradigm such as code-re-utilization, methods abstraction, aggregation for the implementation of SDNSOC on a multi-tenant cloud network. The key benefits obtained using this approach are (i) The network administrator is abstracted from complex-implementation details of SFC. The end-to-end policy composition of different network functions is handled by an object-oriented framework in an automated fashion. We achieve 37% lower latency in SFC composition compared to nearest competitors - SICS and PGA. (ii) Policy conflict detection between the existing traffic rules and incoming traffic is handled by SDNSOC in a scalable manner. The solution scales well on a large cloud network., and 18% faster security policy conflict detection on a cloud network with 100k OpenFlow rules compared to similar works - Brew, and Flowguard.
DOI: 10.1109/nfv-sdn.2017.8169868
发表时间: 2017-11
期刊: 2017 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)
影响因子: --
作者:
Ankur Chowdhary;V. Dixit;N. Tiwari;Sukwha Kyung;Dijiang Huang;Gail-Joon Ahn
通讯作者: Ankur Chowdhary;V. Dixit;N. Tiwari;Sukwha Kyung;Dijiang Huang;Gail-Joon Ahn
软件定义网络和安全
DOI: --
发表时间: 2018
期刊:
影响因子: --
作者:
Dijiang Huang;Ankur Chowdhary;Sandeep Pisharody
通讯作者: Sandeep Pisharody