<p>Conflicts between network policies are frequent in today’s computer networks due to the increasing complexity of network configuration. Resolving policy anomalies usually requires network administrator intervention, which is a time-intensive and error-prone process. This paper presents inference systems for the automatic resolution of OpenFlow anomalies. The approach uses high-level policies to detect conflict correction without policy violations. Our approach is fully automated and does not require interaction with the network administrator. Although there is a multitude of research papers on detecting anomalies in SDN, research to correct those anomalies in an automatic manner is very scarce, if not non-existent. We have formally proven the soundness and completeness of our inference systems. Furthermore, we provide experimental results based on real-life network configurations involving more than 1200 rules. The detection and correction processes exhibit very low computation overhead, in the order of milliseconds, when parallelization is used.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A formal technique for automatic resolution of OpenFlow anomalies

  • Ramtin Aryan,
  • Anis Yazidi,
  • Adel Bouhoula,
  • Paal E. Engelstad

摘要

Conflicts between network policies are frequent in today’s computer networks due to the increasing complexity of network configuration. Resolving policy anomalies usually requires network administrator intervention, which is a time-intensive and error-prone process. This paper presents inference systems for the automatic resolution of OpenFlow anomalies. The approach uses high-level policies to detect conflict correction without policy violations. Our approach is fully automated and does not require interaction with the network administrator. Although there is a multitude of research papers on detecting anomalies in SDN, research to correct those anomalies in an automatic manner is very scarce, if not non-existent. We have formally proven the soundness and completeness of our inference systems. Furthermore, we provide experimental results based on real-life network configurations involving more than 1200 rules. The detection and correction processes exhibit very low computation overhead, in the order of milliseconds, when parallelization is used.