Dependable Policy Enforcement in Traditional Non-SDN Networks

被引:2
|
作者
Odegbile, Olufemi [1 ]
Chen, Shigang [1 ]
Wang, Yuanda [1 ]
机构
[1] Univ Florida, Dept Comp & Informat Sci & Engn, Gainesville, FL 32611 USA
基金
美国国家科学基金会;
关键词
PACKET CLASSIFICATION;
D O I
10.1109/ICDCS.2019.00061
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Middleboxes are widely used in modern networks for a variety of network functions in cybersecurity, performance enhancement, and monitoring. Middlebox policy enforcement is however complex and tedious with unreliable manual re-configuration of legacy routers. The existing solution on automated policy enforcement relies on software-defined networking and does not apply to the traditional non-SDN networks, which remain popular today in enterprise deployment and core networks. This paper proposes a new architecture based entirely on software-defined middleboxes (instead of using software-defined switches in the prior art) to enable dependable and automated policy enforcement in non-SDN networks whose routers forward packets based on traditional routing protocols that are not policy-sensitive. We present a hot-potato enforcement strategy, which is then enhanced with two optimizations for load-balanced policy enforcement. Further enhancements are made to relieve middlebox processing overhead and avoid packet fragmentation due to policy enforcement.
引用
收藏
页码:545 / 554
页数:10
相关论文
共 50 条
  • [31] SAFE-ME: Scalable and Flexible Policy Enforcement in Middlebox Networks
    Xu, Hongli
    Xi, Peng
    Zhao, Gongming
    Liu, Jianchun
    Qian, Chen
    Huang, Liusheng
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (05) : 2246 - 2261
  • [32] Policy Specification and Enforcement in Online Social Networks using MKNF+
    Alizadeh, Mahdi
    Javadi, Seyyed Ahmad
    Amini, Morteza
    Jalili, Rasool
    2012 9TH INTERNATIONAL ISC CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2012, : 48 - 53
  • [33] PolicyCop: An Autonomic QoS Policy Enforcement Framework for Software Defined Networks
    Bari, Md. Faizul
    Chowdhury, Shihabur Rahman
    Ahmed, Reaz
    Boutaba, Raouf
    2013 IEEE WORKSHOP ON SOFTWARE DEFINED NETWORKS FOR FUTURE NETWORKS AND SERVICES (SDN4FNS 2013), 2013,
  • [34] An SDN/NFV-Enabled Enterprise Network Architecture Offering Fine-Grained Security Policy Enforcement
    Lorenz, Claas
    Hock, David
    Scherer, Johann
    Durner, Raphael
    Kellerer, Wolfgang
    Gebert, Steffen
    Gray, Nicholas
    Zinner, Thomas
    Tran-Gia, Phuoc
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (03) : 217 - 223
  • [35] MEASURING THE MONETARY POLICY STANCE IN TURKEY: EFFECTS OF TRADITIONAL AND NON-TRADITIONAL MONETARY POLICY INSTRUMENT
    Tetik, Metin
    Kara, Gorkem
    ROMANIAN JOURNAL OF ECONOMIC FORECASTING, 2021, 24 (03): : 97 - 119
  • [36] Traffic Steering for SDN-based Cellular Networks: Policy Dependent Framework
    Hossen, Md. Sazzad
    Jamalipour, Abbas
    2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2018,
  • [37] Traffic Engineering enforcement in multi-domain SDN orchestration of Multi-Layer (packet/optical) networks
    Mayoral, A.
    Vilalta, R.
    Casellas, R.
    Munoz, R.
    Martinez, R.
    ECOC 2015 41ST EUROPEAN CONFERENCE ON OPTICAL COMMUNICATION, 2015,
  • [38] The Color of Debt: An Examination of Social Networks, Sanctions, and Child Support Enforcement Policy
    David J. Pate
    Race and Social Problems, 2016, 8 : 116 - 135
  • [39] The Color of Debt: An Examination of Social Networks, Sanctions, and Child Support Enforcement Policy
    Pate, David J., Jr.
    RACE AND SOCIAL PROBLEMS, 2016, 8 (01) : 116 - 135
  • [40] A Structuration Agency Approach to Security Policy Enforcement in Mobile Ad Hoc Networks
    Workman, Michael
    Ford, Richard
    Allen, William
    INFORMATION SECURITY JOURNAL, 2008, 17 (5-6): : 267 - 277