2021
DOI: 10.1002/dac.4815
|View full text |Cite
|
Sign up to set email alerts
|

ROCA: Auto‐resolving overlapping and conflicts in Access Control List policies for Software Defined Networking

Abstract: Summary Software‐defined networking (SDN) is a new networking architecture that decouples both the control and management planes from the data plane of forwarding devices. Control and management planes are implemented at a logically centralized entity called the controller. Despite numerous advantages, SDN is more prone to logical errors like loops, black holes, network reachability problems, and access control list (ACL) policies violation. In the existing approaches, the network requirements are specified by… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

0
7
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
8

Relationship

1
7

Authors

Journals

citations
Cited by 12 publications
(9 citation statements)
references
References 22 publications
0
7
0
Order By: Relevance
“…In case of policy change, the proposed mechanisms detect this change and compute the shortest path to install the computed flow rules, in addition to deleting the old flow rules. ROCA [ 108 ] proposes a novel mechanism to detect and resolve network conflicts along with policy overlapping for effective communication in SDN. The proposed approaches help to resolve network policy conflicts and efficiently install flow rules at the data plane.…”
Section: Flow Rule Installation Mechanismsmentioning
confidence: 99%
“…In case of policy change, the proposed mechanisms detect this change and compute the shortest path to install the computed flow rules, in addition to deleting the old flow rules. ROCA [ 108 ] proposes a novel mechanism to detect and resolve network conflicts along with policy overlapping for effective communication in SDN. The proposed approaches help to resolve network policy conflicts and efficiently install flow rules at the data plane.…”
Section: Flow Rule Installation Mechanismsmentioning
confidence: 99%
“…Tere have been various studies on SDN policy forwarding control and policy implementation. Tey include controlling datafows forwarding based on custom policies [3][4][5], implementing trafc scheduling based on policies [6], fltering or redirecting abnormal data fows based on policies [7], network programming language to facilitate network policy creation, development, and deployment [8,9], implementing policy expression as well as policy confict detection and resolution based on specifc data structures [10,11], optimizing policy deployment [12][13][14][15], resolving inconsistencies during policy implementation [16,17], detecting and resolving the overlaps and conficts among the fow rules [18,19], designing policy implementation schemes to adapt to dynamic changes in the link state [20,21], and forth.…”
Section: Introductionmentioning
confidence: 99%
“…Second, the information basis for policy formulation is diferent. In SDN intradomain policy schemes, the intradomain global network state can be read from the controller to formulate address-oriented (IP, MAC, and switch port number) or identifer-oriented (the identifer of the switch, user, or middleware) policies [3,4,10,11,17]; however, in the SDN distributed multidomain environment, there is no central controller that holds interdomain global network state, so SDN cross-domain network information is opaque. Tis would make it impossible to directly develop addressoriented or identifer-oriented interdomain forwarding control policies for SDN interdomains.…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…Access Control List (ACL) is a network security enhancement. It applies a set of ACL rules to each IP packet and determines whether to forward or drop the packet based on its header fields [ 11 ]. ACL is similar to the stateless firewall or packet filtering firewall which provides basic traffic filtering capabilities [ 12 ].…”
Section: Introductionmentioning
confidence: 99%