Contextual, flow-based access control with scalable host-based SDN techniques
Contextual, flow-based access control with scalable host-based SDN techniques
复制标题
DOI:
10.1109/infocom.2016.7524498
复制
发表时间:
2016-04
期刊:
影响因子:
--
通讯作者:
Curtis R. Taylor;D. C. MacFarland;Doran R. Smestad;Craig A. Shue
中科院分区:
文献类型:
--
作者:
Curtis R. Taylor;D. C. MacFarland;Doran R. Smestad;Craig A. Shue
Network operators can better understand their networks when armed with a detailed understanding of the network traffic and host activities. Software-defined networking (SDN) techniques have the potential to improve enterprise security, but the current techniques have well-known data plane scalability concerns and limited visibility into the host's operating context. In this work, we provide both detailed host-based context and fine-grained control of network flows by shifting the SDN agent functionality from the network infrastructure into the end-hosts. We allow network operators to write detailed network policy that can discriminate based on user and program information associated with network flows. In doing so, we find our approach scales far beyond the capabilities of OpenFlow switching hardware, allowing each host to create over 25 new flows per second with no practical bound on the number of established flows in the network.