论文标题

软件定义网络的安全策略模型转换和验证方法

A Security Policy Model Transformation and Verification Approach for Software Defined Networking

论文作者

Meng, Yunfei, Huang, Zhiqiu, Shen, Guohua, Ke, Changbo

论文摘要

软件定义的网络(SDN)已被采用以实施大规模和复杂网络的安全性,因为它具有可编程,抽象,集中式的智能控制以及全局和实时的流量视图。但是,当前基于SDN的安全执法机制要求网络管理人员充分了解网络的基本配置。面对越来越复杂且巨大的SDN网络,我们迫切需要一种新颖的安全策略管理机制,该机制可以完全透明任何基础信息。这就是可以允许网络经理定义高级安全策略而不包含网络的任何基本信息,并且通过模型转换系统,这些高级安全策略可以转换为其相应的较低级别策略,其中包含自动自动信息的基础信息。此外,它应确保由生成的低级策略更新的系统模型可以持有上层策略中定义的所有安全属性。基于这些见解,我们在本文中建议了SDN的安全政策模型转换和验证方法。我们首先介绍了安全策略模型(SPM)的正式定义,该定义可用于指定SDN中使用的安全策略。然后,我们提出了一个基于SDN系统模型和映射规则的模型转换系统,该系统可以使网络管理人员自动将SPM模型转换为相应的基础网络配置策略,即流程表模型(FTM)。为了验证生成的FTM模型更新的SDN系统模型可以保留SPM模型中定义的安全属性,我们根据模型检查设计了一个安全策略验证系统。最后,我们利用一个全面的案例来说明拟议方法的可行性。

Software defined networking (SDN) has been adopted to enforce the security of large-scale and complex networks because of its programmable, abstract, centralized intelligent control and global and real-time traffic view. However, the current SDN-based security enforcement mechanisms require network managers to fully understand the underlying configurations of network. Facing the increasingly complex and huge SDN networks, we urgently need a novel security policy management mechanism which can be completely transparent to any underlying information. That is it can permit network managers to define upper-level security policies without containing any underlying information of network, and by means of model transformation system, these upper-level security policies can be transformed into their corresponding lower-level policies containing underlying information automatically. Moreover, it should ensure system model updated by the generated lower-level policies can hold all of security properties defined in upper-level policies. Based on these insights, we propose a security policy model transformation and verification approach for SDN in this paper. We first present the formal definition of a security policy model (SPM) which can be used to specify the security policies used in SDN. Then, we propose a model transformation system based on SDN system model and mapping rules, which can enable network managers to convert SPM model into corresponding underlying network configuration policies automatically, i.e., flow table model (FTM). In order to verify SDN system model updated by the generated FTM models can hold the security properties defined in SPM models, we design a security policy verification system based on model checking. Finally, we utilize a comprehensive case to illustrate the feasibility of the proposed approach.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源