A Practical Runtime Security Policy Transformation Framework for Software Defined Networks
Yunfei Meng, Changbo Ke, Zhiqiu Huang, Guohua Shen, Chunming Liu,, Xiaojie Feng

TL;DR
This paper presents a practical framework for automatically transforming high-level security policies into flow entries in SDN networks, addressing scalability and management challenges.
Contribution
It introduces a formal method and a runtime framework for security policy transformation in SDN, validated through experiments with POX and Mininet.
Findings
Framework effectively automates policy transformation
Validated with experimental setup showing feasibility
Addresses scalability issues in SDN security management
Abstract
Software-defined networking (SDN) has been widely utilized to enforce the security of traditional networks, thereby promoting the process of transforming traditional networks into SDN networks. However, SDN-based security enforcement mechanisms rely heavily on the security policies containing the underlying information of data plane. With increasing the scale of underlying network, the current security policy management mechanism will confront more and more challenges. The security policy transformation for SDN networks is to research how to transform the high-level security policy without containing the underlying information of data plane into the practical flow entries used by the OpenFlow switches automatically, thereby implementing the automation of security policy management. Based on this insight, a practical runtime security policy transformation framework is proposed in this…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware-Defined Networks and 5G
