SUPC: SDN enabled Universal Policy Checking in Cloud Network

11/01/2018
by   Ankur Chowdhary, et al.
0

Multi-tenant cloud networks have various security and monitoring service functions (SFs) that constitute a service function chain (SFC) between two endpoints. SF rule ordering overlaps and policy conflicts can cause increased latency, service disruption and security breaches in cloud networks. Software Defined Network (SDN) based Network Function Virtualization (NFV) has emerged as a solution that allows dynamic SFC composition and traffic steering in a cloud network. We propose an SDN enabled Universal Policy Checking (SUPC) framework, to provide 1) Flow Composition and Ordering by translating various SF rules into the OpenFlow format. This ensures elimination of redundant rules and policy compliance in SFC. 2) Flow conflict analysis to identify conflicts in header space and actions between various SF rules. Our results show a significant reduction in SF rules on composition. Additionally, our conflict checking mechanism was able to identify several rule conflicts that pose security, efficiency, and service availability issues in the cloud network.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/01/2018

SDN based Network Function Parallelism in Cloud

Network function virtualization (NFV) based service function chaining (S...
research
06/06/2018

A Policy based Security Architecture for Software Defined Networks

As networks expand in size and complexity, they pose greater administrat...
research
05/27/2021

SDN-based Runtime Security Enforcement Approach for Privacy Preservation of Dynamic Web Service Composition

Aiming at the privacy preservation of dynamic Web service composition, t...
research
05/27/2020

A Security Policy Model Transformation and Verification Approach for Software Defined Networking

Software defined networking (SDN) has been adopted to enforce the securi...
research
12/20/2017

Securing Edge Networks with Securebox

The number of mobile and IoT devices connected to home and enterprise ne...
research
09/21/2020

MLSNet: A Policy Complying Multilevel Security Framework for Software Defined Networking

Ensuring that information flowing through a network is secure from manip...
research
09/28/2020

Availability Evaluation of Multi-tenant Service Function Chaining Infrastructures by Multidimensional Universal Generating Function

The Network Function Virtualization (NFV) paradigm has been devised as a...

Please sign up or login with your details

Forgot password? Click here to reset