A formal model of network policy analysis

A formal model of network policy analysis
复制标题

网络策略分析的形式化模型

DOI:
--
复制
发表时间:
2015
期刊:
International Forum on Research and Technologies for Society and Industry Leveraging a better tomorrow
影响因子:
--
通讯作者:
A. Lioy
A. Lioy
中科院分区:
--
文献类型:
--
作者:
Fulvio Valenza;Serena Spinoso;C. Basile;R. Sisto;A. Lioy

文献摘要

被引文献

相似文献

网络拓扑的复杂性以及网络服务的异构性使得网络配置成为一项艰巨的任务,即使对于熟练且经验丰富的管理员来说也是如此。为了降低网络配置的复杂性,管理员利用了网络策略,从而引入了新的错误可能性。事实上,错误和意外的网络行为(例如安全缺陷)可能源自错误的网络策略定义,也可能源自不同域策略之间可能的异常。本文提出了一个用于检测域间和域内策略异常的正式模型。策略异常允许管理员识别他们认为错误或需要监控的所有网络行为。为了验证所提出的解决方案的通用性,该模型已应用于三个策略域(数据包过滤、通信保护和服务功能链),并在不同规模的网络中测试了异常检测分析的影响。
The complexity of network topology together with heterogeneity of network services make the network configuration a hard task, even for skilled and experienced administrators. In order to reduce the complexity of the network configuration, administrators have leveraged network policies, introducing hence new possibility of error. Indeed, erroneous and unexpected network behaviour (e.g., security flaws) can derive from the wrong network policy definition, but also from the possible anomalies among policies of different domains. This paper presents a formal model for detecting inter- and intra-domain policy anomalies. Policy anomalies allow administrators to identify all the network behaviours they consider erroneous or to be monitored. To validate the generality of the proposed solution, the model has been applied to three policy domains (packet filtering, communication protection and service function chaining) and the impact of an anomaly detection analysis was tested in different sized networks.