A framework for managing user-defined security policies to support network security functions

Eunsoo Kim, Kuyju Kim, Seungjin Lee, Jaehoon Jeong, Hyoungshick Kim

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Network Functions Virtualization (NFV) and Software Defined Networking (SDN) make it easier for security administrators to manage security policies on a network system. However, it is still challenging to map high-level security policies defined by users into low-level security policies that can be applied to network security devices. To address this problem, we introduce a framework for effectively managing user-defined security policies for network security functions based on standard interfaces that are currently being standardized in an IETF working group. To show the feasibility of the proposed framework, we implemented a prototype based on the RESTCONF protocol and showed that the proposed framework can be applied in real-world scenarios for network separation, DDoS mitigation and ransomeware prevention.

Original languageEnglish
Title of host publicationProceedings of the 12th International Conference on Ubiquitous Information Management and Communication, IMCOM 2018
PublisherAssociation for Computing Machinery
ISBN (Electronic)9781450363853
DOIs
StatePublished - 5 Jan 2018
Event12th International Conference on Ubiquitous Information Management and Communication, IMCOM 2018 - Langkawi, Malaysia
Duration: 5 Jan 20187 Jan 2018

Publication series

NameACM International Conference Proceeding Series

Conference

Conference12th International Conference on Ubiquitous Information Management and Communication, IMCOM 2018
Country/TerritoryMalaysia
CityLangkawi
Period5/01/187/01/18

Keywords

  • NSF
  • Security management
  • Security policy

Fingerprint

Dive into the research topics of 'A framework for managing user-defined security policies to support network security functions'. Together they form a unique fingerprint.

Cite this