A security policy model transformation and verification approach for software defined networking

被引:2
|
作者
Meng, Yunfei [1 ]
Huang, Zhiqiu [1 ]
Shen, Guohua [1 ]
Ke, Changbo [2 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Coll Comp Sci & Technol, Nanjing 211106, Peoples R China
[2] Nanjing Univ Posts & Telecommun, Sch Comp Sci & Technol, Nanjing 210023, Peoples R China
基金
中国国家自然科学基金;
关键词
SDN; Security policy model; Model transformation; Security policy verification; Model checking;
D O I
10.1016/j.cose.2020.102089
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has been increasingly utilized to enforce the security of complex networks. However SDN-based security enforcement mechanisms rely heavily on some specific security policies containing underlying network information. Facing the increasingly complex and huge SDN networks, we urgently need a novel security policy management mechanism which can be completely transparent to any underlying network information. That is it can permit network managers to define the high-level security policy model without containing any underlying information, and by means of model transformation, high-level security policy model can be automatically transformed into its corresponding lower-level security policy model containing underlying information. Moreover, we must ensure the system model of data plane updated by the low-level security policy model can hold all of security properties defined in high-level security policy model. Based on these insights, we propose a security policy model transformation and verification approach for SDN in this paper. We first specify the security policies used in SDN networks as a formal security policy model (SPM). Then we establish the system model of SDN's data plane and the mapping rules between the policy objects of SPM and the system objects of system model of data plane. Based on these mapping rules, we propose a security policy model transformation mechanism which transforms SPM into the low-level security policy model, RSPM. In order to verify the system model of data plane updated by RSPM can hold all of security properties defined in SPM, we propose a security policy verification mechanism based on model checking techniques and a group of validation conditions. Finally, we utilize a comprehensive case to illustrate the feasibility of this approach. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:12
相关论文
共 50 条
  • [31] Software-Defined Networking for Unmanned Aerial Vehicular Networking and Security: A Survey
    Mccoy, James
    Rawat, Danda B.
    ELECTRONICS, 2019, 8 (12)
  • [32] A New Bandwidth Management Model using Software-Defined Networking Security Threats
    Nisar, Kashif
    Jimson, Emilia Rosa
    Hijazi, Mohd Hanafi bin Ahmad
    Ibrahim, Ag Asri Ag
    Park, Yong Jin
    Welch, Ian
    2019 IEEE 13TH INTERNATIONAL CONFERENCE ON APPLICATION OF INFORMATION AND COMMUNICATION TECHNOLOGIES (AICT 2019), 2019, : 189 - 191
  • [33] Enhancing Network Security through Software Defined Networking (SDN)
    Shin, Seungwon
    Xu, Lei
    Hong, Sungmin
    Gu, Guofei
    2016 25TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN), 2016,
  • [34] A Survey: Typical Security Issues of Software-Defined Networking
    Yifan Liu
    Bo Zhao
    Pengyuan Zhao
    Peiru Fan
    Hui Liu
    中国通信, 2019, 16 (07) : 13 - 31
  • [35] Software Defined Networking Architecture, Security and Energy Efficiency: A Survey
    Rawat, Danda B.
    Reddy, Swetha R.
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (01): : 325 - 346
  • [36] A Framework for Security Services based on Software-Defined Networking
    Jeong, Jaehoon
    Seo, Jihyeok
    Cho, Geumhwan
    Kim, Hyoungshick
    Park, Jung-Soo
    2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 150 - 153
  • [37] Software defined networking for security enhancement in wireless mobile networks
    Ding, Aaron Yi
    Crowcroft, Jon
    Tarkoma, Sasu
    Flinck, Hannu
    COMPUTER NETWORKS, 2014, 66 : 94 - 101
  • [38] Enhancing Multipath TCP Security Through Software Defined Networking
    Melki, Reem
    Hussein, Ali
    Chehab, Ali
    2019 SIXTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2019, : 33 - 38
  • [39] A Survey: Typical Security Issues of Software-Defined Networking
    Liu, Yifan
    Zhao, Bo
    Zhao, Pengyuan
    Fan, Peiru
    Liu, Hui
    CHINA COMMUNICATIONS, 2019, 16 (07) : 13 - 31
  • [40] An Analytical Model for Software Defined Networking: A Network Calculus-based Approach
    Azodolmolky, Siamak
    Nejabati, Reza
    Pazouki, Maryam
    Wieder, Philipp
    Yahyapour, Ramin
    Simeonidou, Dimitra
    2013 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2013, : 1397 - 1402