Towards efficient and secure SDN permission system소프트웨어 정의 네트워크 권한 시스템의 효율성 및 보안성 개선 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 334
  • Download : 0
This dissertation proposes an automation approach to improve the efficiency and security of the software-defined network (SDN) permission system. More specifically, existing SDN permission systems require human intervention in 1) permission reviewing process and 2) permission model generation and implementation process. In the permission reviewing process, a network operator should analyze the SDN application's source code and reads the application's description before installing it to an SDN controller to determine whether the declared permissions in the SDN application are appropriate. In the case of the permission model generation and implementation process, SDN security experts should analyze the assets retained on an SDN controller to design and implement a permission model for the SDN controller. However, such manual tasks are always error-prone and time-consuming, so they degrade security and cause inefficiency in using or building the SDN permission system. To address these problems, this dissertation proposes the novel approaches to automate the two processes (i.e., permission reviewing process, and permission model generation and implementation process) that require human intervention in the SDN permission system. To prove the feasibility of our approaches, we implement prototypes to automate each process and then evaluate them in the context of popular SDN controllers. Our evaluation clearly shows that our approaches enable us to build a more efficient and secure SDN permission system than prior ones.
Advisors
Shin, Seungwonresearcher신승원researcher
Description
한국과학기술원 :정보보호대학원,
Publisher
한국과학기술원
Issue Date
2020
Identifier
325007
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 정보보호대학원, 2020.2,[iv, 90 p. :]

Keywords

software-defined networks▼asecurity▼apermission system▼aautomation▼aefficiency; 소프트웨어 정의 네트워크▼a보안▼a권한 시스템▼a자동화▼a효율성

URI
http://hdl.handle.net/10203/283560
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=907071&flag=dissertation
Appears in Collection
IS-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0