DOCSDN: Dynamic and Optimal Configuration of Software-Defined Networks

02/15/2019
by   Timothy Curry, et al.
0

Networks are designed with functionality, security, performance, and cost in mind. Tools exist to check or optimize individual properties of a network. These properties may conflict, so it is not always possible to run these tools in series to find a configuration that meets all requirements. This leads to network administrators manually searching for a configuration. This need not be the case. In this paper, we introduce a layered framework for optimizing network configuration for functional and security requirements. Our framework is able to output configurations that meet reachability, bandwidth, and risk requirements. Each layer of our framework optimizes over a single property. A lower layer can constrain the search problem of a higher layer allowing the framework to converge on a joint solution. Our approach has the most promise for software-defined networks which can easily reconfigure their logical configuration. Our approach is validated with experiments over the fat tree topology, which is commonly used in data center networks. Search terminates in between 1-5 minutes in experiments. Thus, our solution can propose new configurations for short term events such as defending against a focused network attack.

READ FULL TEXT
research
10/17/2019

FASHION: Functional and Attack graph Secured HybrId Optimization of virtualized Networks

Maintaining a resilient computer network is a delicate task with conflic...
research
08/25/2023

Predictive Network Configuration with Hierarchical Spectral Clustering for Software Defined Vehicles

The increasing connectivity and autonomy of vehicles has led to a growin...
research
04/12/2023

A Security Evaluation Framework for Software-Defined Network Architectures in Data Center Environments

The importance of cloud computing has grown over the last years, which r...
research
12/30/2020

ConfigFix: Interactive Configuration Conflict Resolution for the Linux Kernel

Highly configurable systems are highly complex systems, with the Linux k...
research
02/11/2019

Automated Attack and Defense Framework for 5G Security on Physical and Logical Layers

The 5th generation (5G) network adopts a great number of revolutionary t...
research
09/12/2023

Making Network Configuration Human Friendly

This paper explores opportunities to utilize Large Language Models (LLMs...
research
03/19/2019

Multi-party authorization and conflict mediation for decentralized configuration management processes

Configuration management in networks with highest security demands must ...

Please sign up or login with your details

Forgot password? Click here to reset