Title
Anomaly-free policy composition in software-defined networks
Abstract
Software Defined Networking (SDN) provides considerable simplification of design and deployment of various network applications for large networks. Each application has its own view of network policy and sends its policy to a network hypervisor in which a composed policy is generated from the application policies and deployed into the data plane. A significant challenge for the hypervisor is to detect and resolve both intra and inter policy anomalies during the policy composition. However, current SDN compilers do not consider the policy anomalies well and generate large number of unnecessary rules for the data plane. This leads to a considerable inefficiency in both policy composition and policy deployment. In this paper, we propose a novel framework for policy composition in a SDN hypervisor which takes into account both inter and intra policy anomalies. Moreover, we augment the framework with an efficient insertion transformation mechanism which allows the applications to issue rule insertion and priority change updates. Our evaluation shows that our method is several orders of magnitude more efficient than the state of the art in both policy composition and compiling the rule insertion updates.
Year
DOI
Venue
2016
10.1109/IFIPNetworking.2016.7497226
2016 IFIP Networking Conference (IFIP Networking) and Workshops
Keywords
Field
DocType
priority change updates,rule insertion,insertion transformation mechanism,SDN hypervisor,policy deployment,data plane,inter policy anomaly,intra policy anomaly,network hypervisor,anomaly-free policy composition,SDN compilers,software defined networking
Data structure,Forwarding plane,Software deployment,Network security policy,Computer science,Hypervisor,Inefficiency,Compiler,Software-defined networking,Distributed computing
Conference
Citations 
PageRank 
References 
1
0.35
19
Authors
4
Name
Order
Citations
PageRank
Mohsen Rezvani18211.39
Aleksandar Ignjatovic255649.24
Maurice Pagnucco335740.74
Sanjay Jha41745157.12