Dynamic ACL Policy Implementation in Software Defined Networks
Farrukh Shoukat Ali, Rashid Amin, Muzammal Majeed, Muhammad Munwar Iqbal · 2022
The Access Control List (ACL) policy restricts data transmission due to the network's dynamic behaviour and complicated relationships. As network scalability increases in a heterogeneous network environment, people can't handle so many nodes and data on traditional and Software Defined Networks (SDN). The SDN controller stores ACL policies and matches data packets based on network activity. Events and changing system behaviour cause superfluous processing and unauthorized access, which delays the controller owing to multiple users and data, affecting end-to-end data packet delays and its operation. This research proposes a scalable, efficient, lightweight, adaptive framework and a machine learning (ML) based approach for SDNs with the features of a centralized database. The proposed approach, i.e., d-CAP intercepts real network traffic, manipulates data flow properties based on generated network events, forms a dataset using OpenFlow, and correlates controller packets with active classified hosts. The system itself learns and maps ACL policies based on high and low-level attributes, classifies hosts, and calculates the best-routed path. Simultaneously, it predicts and revokes ACL policies for new and existing users and removes obsolete flow rules from the centralized database. It reduces active users' overhead by computing the network path, preventing unauthorized access, and lowering the network's environmental threats. We trained, tested, and evaluated d-CAP publicly available datasets based on IoT and non-IoT traces. Our development outperforms non-ML based methodologies.