A model for the analysis of security policies in service function chains
Title | A model for the analysis of security policies in service function chains |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Durante, L., Seno, L., Valenza, F., Valenzano, A. |
Conference Name | 2017 IEEE Conference on Network Softwarization (NetSoft) |
ISBN Number | 978-1-5090-6008-5 |
Keywords | Ad hoc networks, Analytical models, Collaboration, computer network security, cryptography, formal model, Monitoring, network function virtualization, NFV, policy-based governance, program verification, pubcrawl, SDN, security policies, Security Policies Analysis, service function chains, SFC, Software, software defined networking, software tools, Virtual private networks, virtualisation |
Abstract | Two emerging architectural paradigms, i.e., Software Defined Networking (SDN) and Network Function Virtualization (NFV), enable the deployment and management of Service Function Chains (SFCs). A SFC is an ordered sequence of abstract Service Functions (SFs), e.g., firewalls, VPN-gateways, traffic monitors, that packets have to traverse in the route from source to destination. While this appealing solution offers significant advantages in terms of flexibility, it also introduces new challenges such as the correct configuration and ordering of SFs in the chain to satisfy overall security requirements. This paper presents a formal model conceived to enable the verification of correct policy enforcements in SFCs. Software tools based on the model can then be designed to cope with unwanted network behaviors (e.g., security flaws) deriving from incorrect interactions of SFs of the same SFC. |
URL | https://ieeexplore.ieee.org/document/8004230/ |
DOI | 10.1109/NETSOFT.2017.8004230 |
Citation Key | durante_model_2017 |
- pubcrawl
- virtualisation
- Virtual private networks
- software tools
- software defined networking
- Software
- SFC
- service function chains
- Security Policies Analysis
- security policies
- SDN
- Ad hoc networks
- program verification
- policy-based governance
- NFV
- network function virtualization
- Monitoring
- formal model
- Cryptography
- computer network security
- collaboration
- Analytical models