A Fine-Grained Detection Mechanism for SDN Rule Collision

1Citations
Citations of this article
1Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The rules issued by third-party applications may have direct violations or indirect violations with existing security flow rules in the SDN (software-defined network), thereby leading to the failure of security rules. Currently, existing methods cannot detect the rule collision in a comprehensive and fine-grained manner. This paper proposes a deep detection mechanism for rule collision that can detect grammatical errors in the flow rules themselves, and can also detect direct and indirect rule collisions between third-party and security applications based on the set intersection method. In addition, our mechanism can effectively and automatically resolve the rule collision. Finally, we implement the detection mechanism in the RYU controller, and use Mininet to evaluate the function and performance. The results show that the mechanism proposed in this paper can accurately detect the static, dynamic and dependency collisions of flow rules, and ensure that the decline of throughput of the northbound interface of the SDN network is controlled at 20%.

Cite

CITATION STYLE

APA

Xiaochen, Q., Shihui, Z., Lize, G., & Yongmei, C. (2019). A Fine-Grained Detection Mechanism for SDN Rule Collision. In Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST (Vol. 279, pp. 549–559). Springer Verlag. https://doi.org/10.1007/978-3-030-19086-6_60

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free