Building a Security Policy Tree for SDN Controllers

Sergey V. Morzhov, Valery A. Sokolov, Mikhail A. Nikitinskiy, Dmitry Ju. Chalyy · 2018

A firewall is a main classical tool to control and manage network traffic in a local network. Its job is to compare the streams passing through it with the established safety rules. These rules, which are often also called as security policy, can be defined both before and during the work of the firewall. Security policy management, especially when large enterprise networks are concerned, is complex and error-prone task. Thus, firewall filtering rules have to be written and organized carefully in order to implement the security policy correctly. Moreover, the process of modifying a rule or inserting the new one must be performed after a thorough analysis of the relations between the modified or newly inserted rule and rules, which already exist in the security policy. In this paper, the authors propose their own classification of collisions that may occur among the rules of the security policy. In addition, the authors present their new efficient algorithm for detecting and resolving collisions in firewall rules by the example of the Floodlight SDN controller. This algorithm can be used to find security holes in the rules set, to minimize the number of rules in the existing security policy or to prevent appearance of any collisions in actual time.

Read the paper · More papers on PaperTik