OpenSec: Policy-Based Security Using Software-Defined Networking

被引:58
|
作者
Lara, Adrian [1 ]
Ramamurthy, Byrav [1 ]
机构
[1] Univ Nebraska, Dept Comp Sci & Engn, Lincoln, NE 68588 USA
基金
美国国家科学基金会;
关键词
Software-defined networking; OpenFlow; network security; policy-based network management; policy specification; MANAGEMENT;
D O I
10.1109/TNSM.2016.2517407
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the popularity of software-defined networks (SDN) and OpenFlow increases, policy-driven network management has received more attention. Manual configuration of multiple devices is being replaced by an automated approach where a software-based, network-aware controller handles the configuration of all network devices. Software applications running on top of the network controller provide an abstraction of the topology and facilitate the task of operating the network. We propose OpenSec, an OpenFlow-based security framework that allows a network security operator to create and implement security policies written in human-readable language. Using OpenSec, the user can describe a flow in terms of OpenFlow matching fields, define which security services must be applied to that flow (deep packet inspection, intrusion detection, spam detection, etc.) and specify security levels that define how OpenSec reacts if malicious traffic is detected. In this paper, we first provide a more detailed explanation of how OpenSec converts security policies into a series of OpenFlow messages needed to implement such a policy. Second, we describe how the framework automatically reacts to security alerts as specified by the policies. Third, we perform additional experiments on the GENI testbed to evaluate the scalability of the proposed framework using existing datasets of campus networks. Our results show that up to 95% of attacks in an existing data set can be detected and 99% of malicious source nodes can be blocked automatically. Furthermore, we show that our policy specification language is simpler while offering fast translation times compared to existing solutions.
引用
收藏
页码:30 / 42
页数:13
相关论文
共 50 条
  • [1] A Policy-Based Security Architecture for Software-Defined Networks
    Varadharajan, Vijay
    Karmakar, Kallol
    Tupakula, Uday
    Hitchens, Michael
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (04) : 897 - 912
  • [2] Quality of Service and Congestion Control in Software-Defined Networking Using Policy-Based Routing
    Ali, Inayat
    Hong, Seungwoo
    Cheung, Taesik
    APPLIED SCIENCES-BASEL, 2024, 14 (19):
  • [3] Analysis of Policy-Based Security Management System in Software-Defined Networks
    Sood, Keshav
    Karmakar, Kallol Krishna
    Varadharajan, Vijay
    Tupakula, Uday
    Yu, Shui
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (04) : 612 - 615
  • [4] Policy-Based Management for Green Mobile Networks Through Software-Defined Networking
    Huertas Celdran, Alberto
    Gil Perez, Manuel
    Garcia Clemente, Felix J.
    Martinez Perez, Gregorio
    MOBILE NETWORKS & APPLICATIONS, 2019, 24 (02): : 657 - 666
  • [5] Policy-Based Management for Green Mobile Networks Through Software-Defined Networking
    Alberto Huertas Celdrán
    Manuel Gil Pérez
    Félix J. García Clemente
    Gregorio Martínez Pérez
    Mobile Networks and Applications, 2019, 24 : 657 - 666
  • [6] Leveraging software-defined networking for security policy enforcement
    Liu, Jiaqiang
    Li, Yong
    Wang, Huandong
    Jin, Depeng
    Su, Li
    Zeng, Lieguang
    Vasilakos, Thanos
    INFORMATION SCIENCES, 2016, 327 : 288 - 299
  • [7] A Framework for Security Services based on Software-Defined Networking
    Jeong, Jaehoon
    Seo, Jihyeok
    Cho, Geumhwan
    Kim, Hyoungshick
    Park, Jung-Soo
    2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 150 - 153
  • [8] A model transformation based security policy automatic management framework for software-defined networking
    Meng, Yunfei
    Ke, Changbo
    Huang, Zhiqiu
    COMPUTERS & SECURITY, 2024, 142
  • [9] Policy-based QoS Management Framework for Software-Defined Networks
    Al-Jawad, Ahmed
    Shah, Purav
    Gemikonakli, Orhan
    Trestian, Ramona
    2018 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2018), 2018,
  • [10] Policy-based Orchestration of NFV Services in Software-Defined Networks
    Giotis, K.
    Kryftis, Y.
    Maglaris, V.
    2015 1ST IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT), 2015,