Dependable Policy Enforcement in Traditional Non-SDN Networks

被引:2
|
作者
Odegbile, Olufemi [1 ]
Chen, Shigang [1 ]
Wang, Yuanda [1 ]
机构
[1] Univ Florida, Dept Comp & Informat Sci & Engn, Gainesville, FL 32611 USA
基金
美国国家科学基金会;
关键词
PACKET CLASSIFICATION;
D O I
10.1109/ICDCS.2019.00061
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Middleboxes are widely used in modern networks for a variety of network functions in cybersecurity, performance enhancement, and monitoring. Middlebox policy enforcement is however complex and tedious with unreliable manual re-configuration of legacy routers. The existing solution on automated policy enforcement relies on software-defined networking and does not apply to the traditional non-SDN networks, which remain popular today in enterprise deployment and core networks. This paper proposes a new architecture based entirely on software-defined middleboxes (instead of using software-defined switches in the prior art) to enable dependable and automated policy enforcement in non-SDN networks whose routers forward packets based on traditional routing protocols that are not policy-sensitive. We present a hot-potato enforcement strategy, which is then enhanced with two optimizations for load-balanced policy enforcement. Further enhancements are made to relieve middlebox processing overhead and avoid packet fragmentation due to policy enforcement.
引用
收藏
页码:545 / 554
页数:10
相关论文
共 50 条
  • [41] Analysis and Research on the Traditional Congestion Control Policy and Active Networks Congestion Control Policy
    Liu, Chong
    Meng, Yanjuan
    Zhao, Xiuming
    He, Zhiqiang
    An, Wenguang
    2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, : 4489 - 4491
  • [42] SDN-based offloading policy to reduce the delay in fog-vehicular networks
    Alla Abbas Khadir
    Seyed Amin Hosseini Seno
    Peer-to-Peer Networking and Applications, 2021, 14 : 1261 - 1275
  • [43] Networked Enforcement in the Common Fisheries Policy through Data Sharing: Is There Room Left for Traditional Accountability Paradigms?
    Cacciatore, Federica
    Eliantonio, Mariolina
    EUROPEAN JOURNAL OF RISK REGULATION, 2019, 10 (03) : 522 - 537
  • [44] Emulation Performance Study of Traffic-Aware Policy Enforcement in Software Defined Networks
    Vawter, Isaac
    Pan, Deng
    Ma, Wenrui
    2014 IEEE 11TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS (MASS), 2014, : 775 - 780
  • [45] Deny-by-Default Distributed Security Policy Enforcement in Mobile Ad Hoc Networks
    Alicherry, Mansoor
    Keromytis, Angelos D.
    Stavrou, Angelos
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, 2009, 19 : 41 - +
  • [46] Law Enforcement Officer Versus Non-Law Enforcement Officer Status as a Longitudinal Predictor of Traditional and Emerging Cardiovascular Risk Factors
    Wright, Bruce R.
    Barbosa-Leiker, Celestina
    Hoekstra, Trynke
    JOURNAL OF OCCUPATIONAL AND ENVIRONMENTAL MEDICINE, 2011, 53 (07) : 730 - 734
  • [47] Securing Zero Trust Networks: the Decentralized Host-to-Host Authentication Policy Enforcement
    Spanier, Adam
    Zhao, Rui
    Huang, Pei-Chi
    2023 IEEE 22ND INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, BIGDATASE, CSE, EUC, ISCI 2023, 2024, : 1518 - 1523
  • [48] ASPE: attribute-based secure policy enforcement in vehicular ad hoc networks
    Huang, Dijiang
    Verma, Mayank
    AD HOC NETWORKS, 2009, 7 (08) : 1526 - 1535
  • [49] Non-traditional monetary policy and the future of the financial industries
    Thorbecke, Willem
    INTERNATIONAL JOURNAL OF ECONOMIC POLICY STUDIES, 2021, 15 (01) : 5 - 21
  • [50] Non-traditional monetary policy and the future of the financial industries
    Willem Thorbecke
    International Journal of Economic Policy Studies, 2021, 15 : 5 - 21