A Security Policy Model Transformation and Verification Approach for Software Defined Networking
Yunfei Meng, Zhiqiu Huang, Guohua Shen, Changbo Ke

TL;DR
This paper introduces a formal approach for transforming high-level security policies into detailed network configurations in SDN, ensuring security properties are maintained through model verification.
Contribution
It presents a novel formal security policy model transformation system and verification method for SDN, enabling automatic policy conversion and security assurance.
Findings
Automated transformation from high-level policies to network configurations.
Verification system ensures security properties are preserved.
Case study demonstrates the approach's feasibility.
Abstract
Software defined networking (SDN) has been adopted to enforce the security of large-scale and complex networks because of its programmable, abstract, centralized intelligent control and global and real-time traffic view. However, the current SDN-based security enforcement mechanisms require network managers to fully understand the underlying configurations of network. Facing the increasingly complex and huge SDN networks, we urgently need a novel security policy management mechanism which can be completely transparent to any underlying information. That is it can permit network managers to define upper-level security policies without containing any underlying information of network, and by means of model transformation system, these upper-level security policies can be transformed into their corresponding lower-level policies containing underlying information automatically. Moreover, it…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware-Defined Networks and 5G · Synthetic Organic Chemistry Methods · Network Packet Processing and Optimization
