Efficient Distribution of Security Policy Filtering Rules in Software Defined Networks - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2020

Efficient Distribution of Security Policy Filtering Rules in Software Defined Networks

Résumé

Software Defined Networks administrators can specify and smoothly deploy abstract network-wide policies, and then the controller acting as a central authority implements them in the flow tables of the network switches. The rule sets of these policies are specified in the forwarding tables, which are usually accessed using very expensive and power-hungry ternary content-addressable memory (TCAM). Consequently, a given table can only contain a limited number of rules. However, various applications need large rule sets to perform filtering on diverse flows. In this paper, we propose several algorithms for decomposing and distributing a rule set on network switches of limited flow tables size, while preserving the network policy semantics. Through experiments on several rule sets with single and multiple dimensions, we evaluate and analyse the performance of our rule placement techniques. Our results show that our proposals are efficient in practice.
Fichier principal
Vignette du fichier
main.pdf (613.86 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03036350 , version 1 (02-12-2020)

Identifiants

  • HAL Id : hal-03036350 , version 1

Citer

Ahmad Abboud, Rémi Garcia, Abdelkader Lahmadi, Michaël Rusinowitch, Adel Bouhoula. Efficient Distribution of Security Policy Filtering Rules in Software Defined Networks. NCA 2020 - 19th IEEE International Symposium on Network Computing and Applications, Nov 2020, Online conference, France. ⟨hal-03036350⟩
117 Consultations
163 Téléchargements

Partager

Gmail Facebook X LinkedIn More