论文标题

MLSNET:符合软件定义网络的多级安全框架的策略

MLSNet: A Policy Complying Multilevel Security Framework for Software Defined Networking

论文作者

Achleitner, Stefan, Burke, Quinn, McDaniel, Patrick, Jaeger, Trent, La Porta, Thomas, Krishnamurthy, Srikanth

论文摘要

确保通过网络流过网络的信息可以保护不操纵和未经授权的各方窃听是网络管理员的重要任务。许多网络攻击都依赖缺乏网络级信息流控制来成功损害受害者网络。一旦对手利用了初始入口点,他们就可以在网络中窃听并横向移动(例如,扫描和穿透内部节点)以进一步实现其恶意目标。在本文中,我们提出了一个新颖的多级安全性(MLS)框架,以在网络内执行安全的节点信息流策略,并大大降低了已经穿透了它的对手可用的攻击表面。与在网络端点上执行策略的计算机网络中对多级安全性的先前工作相反,我们通过将任务移至控制器并将此服务透明地提供给网络的所有节点来利用软件定义网络(SDN)的集中化。我们的框架MLSNET正式将符合策略的网络配置(即SDN交换机上的流量规则集)形式化为网络优化问题,并且(1)目标的目标最大化满足所有安全性约束的流量,以及(2)最小化任何可用剩余流的安全性的安全性。我们证明,MLSNet可以安全地路由满足安全限制的流动(例如,在执行的基准测试中> 80%的流量),并以最小的安全成本路由其余流量。

Ensuring that information flowing through a network is secure from manipulation and eavesdropping by unauthorized parties is an important task for network administrators. Many cyber attacks rely on a lack of network-level information flow controls to successfully compromise a victim network. Once an adversary exploits an initial entry point, they can eavesdrop and move laterally within the network (e.g., scan and penetrate internal nodes) to further their malicious goals. In this paper, we propose a novel multilevel security (MLS) framework to enforce a secure inter-node information flow policy within the network and therein vastly reduce the attack surface available to an adversary who has penetrated it. In contrast to prior work on multilevel security in computer networks which relied on enforcing the policy at network endpoints, we leverage the centralization of software-defined networks (SDNs) by moving the task to the controller and providing this service transparently to all nodes in the network. Our framework, MLSNet, formalizes the generation of a policy compliant network configuration (i.e., set of flow rules on the SDN switches) as network optimization problems, with the objectives of (1) maximizing the number of flows satisfying all security constraints and (2) minimizing the security cost of routing any remaining flows to guarantee availability. We demonstrate that MLSNet can securely route flows that satisfy the security constraints (e.g., >80% of flows in a performed benchmark) and route the remaining flows with a minimal security cost.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源