Contextual, flow-based access control with scalable host-based SDN techniques

Contextual, flow-based access control with scalable host-based SDN techniques
复制标题

DOI:
10.1109/infocom.2016.7524498
复制
发表时间:
2016-04
期刊:
IEEE INFOCOM 2016 - The 35th Annual IEEE International Conference on Computer Communications
影响因子:
--
通讯作者:
Curtis R. Taylor;D. C. MacFarland;Doran R. Smestad;Craig A. Shue
Curtis R. Taylor;D. C. MacFarland;Doran R. Smestad;Craig A. Shue
中科院分区:
其他
文献类型:
--
作者:
Curtis R. Taylor;D. C. MacFarland;Doran R. Smestad;Craig A. Shue

文献摘要

被引文献

相似文献

当网络运营商详细了解网络流量和主机活动时,他们可以更好地了解自己的网络。软件定义网络(SDN)技术具有提高企业安全性的潜力,但是当前技术具有众所周知的数据平面可扩展性问题和对主机的操作上下文的有限可见性。在这项工作中,我们通过将SDN代理功能从网络基础设施转移到终端主机,提供了详细的基于主机的上下文和对网络流的细粒度控制。我们允许网络运营商编写详细的网络策略,可以根据与网络流相关的用户和程序信息进行区分。在这样做的过程中,我们发现我们的方法远远超出了OpenFlow交换硬件的能力,允许每个主机每秒创建超过25个新流,而对网络中已建立的流的数量没有实际限制。
Network operators can better understand their networks when armed with a detailed understanding of the network traffic and host activities. Software-defined networking (SDN) techniques have the potential to improve enterprise security, but the current techniques have well-known data plane scalability concerns and limited visibility into the host's operating context. In this work, we provide both detailed host-based context and fine-grained control of network flows by shifting the SDN agent functionality from the network infrastructure into the end-hosts. We allow network operators to write detailed network policy that can discriminate based on user and program information associated with network flows. In doing so, we find our approach scales far beyond the capabilities of OpenFlow switching hardware, allowing each host to create over 25 new flows per second with no practical bound on the number of established flows in the network.