A Network Access Control solution combining OrBAC and SDN
Rafael Roque Aschoff, Daniel Rosendo, Marcos Machado, Alexandre Hugo Ribeiro dos Santos, Djamel Fawzi Hadj Sadok · 2017
Standard Port-based Network Access Control (NAS) with tagged Virtual Local Area Networks (VLANs) systems are useful to authenticate users within an isolated network environment. This approach on its own, however, lacks the flexibility and granularity level that new generation networks based on SDN (Software Defined Networking) can provide. The flow-based access control provides a more appropriate granularity to enforce network policies. In this paper, we propose a novel solution named SDN-based Network Access Control (S-NAC) that provides authentication and authorization of clients and servers based on high-level policies enforced at flow level. The solution has been implemented, deployed and tested over emulated and real networks.