Towards policy unification for enterprise network security

Sadiq T. Yakasai, Fu‐Chun Zheng, Chris G. Guy · 2017

The task of securing the enterprise network currently involves the use of several specialized devices (i.e. 'middleboxes') to provide specific functions in order to satisfy a set of high-level defined objectives. With only a loose common goal of securing the network, these employed devices could not be more distinct in functionality - from network access-control, vulnerability assessment, to intrusion detection and prevention systems, to firewalls. Network operators are therefore faced with the immense challenge of having to manage hundreds to thousands of configuration lines across these devices, in addition to providing the necessary coordination between these disparate functions, in order to effectively secure the network. Towards the aim of unifying policy enforcement across network security functions, we present an architecture that is based on Software-Defined Networking (SDN). Our solution extends the IEEE 802.1X framework and abstracts network endpoint connectivity context, thereby allowing for cross-functional policy composition and enforcement. We present a proof-of-concept prototype and performed some experimental evaluation, as well as outlining our future research directions.

Read the paper · More papers on PaperTik