A Policy based Security Architecture for Software Defined Networks
Vijay Varadharajan, Kallol Karmakar, Uday Tupakula, Michael Hitchens

TL;DR
This paper proposes a policy-driven security architecture for SDNs that enables fine-grained, path, and flow-based security policies across multiple domains, enhancing end-to-end service security and attack resilience.
Contribution
It introduces a novel policy language and architecture for specifying and enforcing security policies in multi-domain SDNs, including path and flow-based controls.
Findings
Demonstrates effective security policy specification for SDN communications.
Shows architecture's ability to counteract various security attacks.
Analyzes performance and security effectiveness of the proposed system.
Abstract
As networks expand in size and complexity, they pose greater administrative and management challenges. Software Defined Networks (SDN) offer a promising approach to meeting some of these challenges. In this paper, we propose a policy driven security architecture for securing end to end services across multiple SDN domains. We develop a language based approach to design security policies that are relevant for securing SDN services and communications. We describe the policy language and its use in specifying security policies to control the flow of information in a multi-domain SDN. We demonstrate the specification of fine grained security policies based on a variety of attributes such as parameters associated with users and devices/switches, context information such as location and routing information, and services accessed in SDN as well as security attributes associated with the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
