Software-defined networking (SDN) has been widely utilized to enforce the security of traditional networks, thereby promoting the process of transforming traditional networks into SDN networks. However, SDN-based security enforcement mechanisms rely heavily on the security policies containing the underlying information of data plane. With increasing the scale of underlying network, the current security policy management mechanism will confront more and more challenges. The security policy transformation for SDN networks is to research how to transform the high-level security policy without containing the underlying information of data plane into the practical flow entries used by the OpenFlow switches automatically, thereby implementing the automation of security policy management. Based on this insight, a practical runtime security policy transformation framework is proposed in this paper. First of all, we specify the security policies used by SDN networks as a system model of security policy (SPM). From the theoretical level, we establish the system model for SDN network and propose a formal method to transform SPM into the system model of flow entries automatically. From the practical level, we propose a runtime security policy transformation framework to solve the problem of how to find a connected path for each relationship of SPM in the data plane, as well as how to generate the practical flow entries according to the system model of flow entries. In order to validate the feasibility and effectiveness of the framework, we set up an experimental system and implement the framework with POX controller and Mininet emulator.
翻译:软件定义的网络(SDN)被广泛用来加强传统网络的安全,从而推动传统网络转变为SDN网络的进程;然而,SDN基于的安全执行机制严重依赖包含数据平面基本信息的安全政策。随着基础网络规模的扩大,目前的安全政策管理机制将面临越来越多的挑战。SDN网络的安全政策转型是研究如何在不包含数据平面基本信息的情况下将高层次安全政策自动转化为OpenFlow开关使用的实际流程条目,从而实施安全政策管理自动化。基于这一洞察力,本文件提出了一个实际运行的安保政策变革框架。首先,我们具体规定SDN网络使用的安全政策作为安全政策的系统模式(SPM)。从理论层面,我们为SDN网络建立了系统模式,并提出了将SPMT自动转化为流程输入系统模式的正式方法。从实际层面出发,我们建议一个运行的安保政策转型框架,以解决如何为SPM平面的每一种关系找到连接路径的问题。首先,我们把SPMDMS网络的运行时间框架指定为系统模型的系统模式模式模式模式模式,然后将运行到PON框架。我们如何实现系统的可行性框架。