Programmable In-Network Security for Context-aware BYOD Policies

08/04/2019
by   Qiao Kang, et al.
0

Bring Your Own Device (BYOD) has become the new norm in enterprise networks, but BYOD security remains a top concern. Context-aware security, which enforces access control based on dynamic runtime context, holds much promise. Recent work has developed SDN solutions to collect device context for network-wide access control in a central controller. However, the central controller poses a bottleneck that can become an attack target, and processing context changes at remote software has low agility. We present a new paradigm, programmable in-network security (Poise), which is enabled by the emergence of programmable switches. At the heart of Poise is a novel switch primitive, which can be programmed to support a wide range of context-aware policies in hardware. Users of Poise specify concise policies, and Poise compiles them into different instantiations of the security primitive in P4. Compared to centralized SDN defenses, Poise is resilient to control plane saturation attacks, and it dramatically increases defense agility.

READ FULL TEXT
research
06/11/2019

Secure Software-Defined Networking Based on Blockchain

Software-Defined Networking (SDN) separates the network control plane an...
research
01/24/2020

Software-Defined Location Privacy Protection for Vehicular Networks

While the adoption of connected vehicles is growing, security and privac...
research
07/07/2018

Gargoyle: A Network-based Insider Attack Resilient Framework for Organizations

`Anytime, Anywhere' data access model has become a widespread IT policy ...
research
10/27/2017

Fronthaul-Aware Software-Defined Wireless Networks: Resource Allocation and User Scheduling

Software-defined networking (SDN) provides an agile and programmable way...
research
05/25/2022

P4Filter: A two level defensive mechanism against attacks in SDN using P4

The advancements in networking technologies have led to a new paradigm o...
research
02/20/2023

Programmable System Call Security with eBPF

System call filtering is a widely used security mechanism for protecting...
research
01/21/2020

LOcAl DEcisions on Replicated States (LOADER) in programmable data planes: programming abstraction and experimental evaluation

Programmable data planes recently emerged as a prominent innovation in S...

Please sign up or login with your details

Forgot password? Click here to reset