The Experts below are selected from a list of 31722 Experts worldwide ranked by ideXlab platform
Myungjin Lee - One of the best experts on this subject based on the ideXlab platform.
-
Fault Localization in Large-Scale Network Policy Deployment
2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) facilitate network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT-a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
-
ICDCS - Fault Localization in Large-Scale Network Policy Deployment
2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Rao Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) facilitate network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT–a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
-
Fault Localization in Large-Scale Network Policy Deployment
arXiv: Networking and Internet Architecture, 2017Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Rao Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) are easing network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT---a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
Praveen Tammana - One of the best experts on this subject based on the ideXlab platform.
-
Fault Localization in Large-Scale Network Policy Deployment
2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) facilitate network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT-a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
-
ICDCS - Fault Localization in Large-Scale Network Policy Deployment
2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Rao Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) facilitate network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT–a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
-
Fault Localization in Large-Scale Network Policy Deployment
arXiv: Networking and Internet Architecture, 2017Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Rao Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) are easing network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT---a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
Stere Preda - One of the best experts on this subject based on the ideXlab platform.
-
Model-driven security Policy Deployment: property oriented approach
2010Co-Authors: Stere Preda, Frédéric Cuppens, Nora Cuppens-boulahia, Joaquin Garcia Alfaro, Laurent ToutainAbstract:We address the issue of formally validating the Deployment of access control security policies. We show how the use of a formal expression of the security requirements, related to a given system, ensures the Deployment of an anomaly free abstract security Policy. We also describe how to develop appropriate algorithms by using a theorem proving approach with a modeling language allowing the specification of the system, of the link between the system and the Policy, and of certain target security properties. The result is a set of proved algorithms that constitute the certified technique for a reliable security Policy Deployment.
-
ESSoS - Model-Driven security Policy Deployment: property oriented approach
Lecture Notes in Computer Science, 2010Co-Authors: Stere Preda, Frédéric Cuppens, Nora Cuppens-boulahia, Joaquin Garcia Alfaro, Laurent ToutainAbstract:We address the issue of formally validating the Deployment of access control security policies. We show how the use of a formal expression of the security requirements, related to a given system, ensures the Deployment of an anomaly free abstract security Policy. We also describe how to develop appropriate algorithms by using a theorem proving approach with a modeling language allowing the specification of the system, of the link between the system and the Policy, and of certain target security properties. The result is a set of proved algorithms that constitute the certified technique for a reliable security Policy Deployment.
-
Semantic context aware security Policy Deployment
2009Co-Authors: Stere Preda, Frédéric Cuppens, Nora Cuppens-boulahia, Joaquin Garcia Alfaro, Laurent Toutain, Yehia El RakaibyAbstract:The successful Deployment of a security Policy is closely related not only to the complexity of the security requirements but also to the capabilities/functionalities of the security devices. The complexity of the security requirements is additionally increased when contextual constraints are taken into account. Such situations appear when addressing the dynamism of some security requirements or when searching a finer granularity for the security rules. The context denotes those specific conditions in which the security requirements are to be met. (Re)deploying a contextual security Policy depends on the security device functionalities: either (1) the devices include all functionalities necessary to deal with a context and the Policy is consequently deployed for ensuring its automatic changes or (2) the devices do not have the right functionalities to entirely interpret a contextual requirement. We present a solution to cope with this issue: the (re)Deployment of access control policies in a system that lacks the necessary functionalities to deal with contexts.
-
AsiaCCS - Semantic context aware security Policy Deployment
Proceedings of the 4th International Symposium on Information Computer and Communications Security - ASIACCS '09, 2009Co-Authors: Stere Preda, Frédéric Cuppens, Nora Cuppens-boulahia, Laurent Toutain, Joaquin Garcia Alfaro, Yehia ElrakaibyAbstract:The successful Deployment of a security Policy is closely related not only to the complexity of the security requirements but also to the capabilities/functionalities of the security devices. The complexity of the security requirements is additionally increased when contextual constraints are taken into account. Such situations appear when addressing the dynamism of some security requirements or when searching a finer granularity for the security rules. The context denotes those specific conditions in which the security requirements are to be met. (Re)deploying a contextual security Policy depends on the security device functionalities: either (1) the devices include all functionalities necessary to deal with a context and the Policy is consequently deployed for ensuring its automatic changes or (2) the devices do not have the right functionalities to entirely interpret a contextual requirement. We present a solution to cope with this issue: the (re)Deployment of access control policies in a system that lacks the necessary functionalities to deal with contexts.
-
reliable process for security Policy Deployment
International Conference on Security and Cryptography, 2007Co-Authors: Stere Preda, Frédéric Cuppens, Nora Cuppensboulahia, Joaquin Garcia Alfaro, Laure ToutaiAbstract:We focus in this paper on the problem of configuring and managing network security devices, such as Firewalls, Virtual Private Network (VPN) tunnels, and Intrusion Detection Systems (IDSs). Our proposal is the following. First, we formally specify the security requirements of a given system by using an expressive access control model. As a result, we obtain an abstract security Policy, which is free of ambiguities, redundancies or unnecessary details. Second, we deploy such an abstract Policy through a set of automatic compilations into the security devices of the system. This proposed Deployment process not only simplifies the security administrator’s job, but also guarantees a resulting configuration free of anomalies and/or inconsistencies.
Pavan Mamillapalli - One of the best experts on this subject based on the ideXlab platform.
-
Fault Localization in Large-Scale Network Policy Deployment
2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) facilitate network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT-a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
-
ICDCS - Fault Localization in Large-Scale Network Policy Deployment
2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Rao Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) facilitate network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT–a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
-
Fault Localization in Large-Scale Network Policy Deployment
arXiv: Networking and Internet Architecture, 2017Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Rao Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) are easing network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT---a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
Chandra Nagarajan - One of the best experts on this subject based on the ideXlab platform.
-
Fault Localization in Large-Scale Network Policy Deployment
2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) facilitate network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT-a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
-
ICDCS - Fault Localization in Large-Scale Network Policy Deployment
2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Rao Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) facilitate network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT–a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.
-
Fault Localization in Large-Scale Network Policy Deployment
arXiv: Networking and Internet Architecture, 2017Co-Authors: Praveen Tammana, Chandra Nagarajan, Pavan Mamillapalli, Ramana Rao Kompella, Myungjin LeeAbstract:The recent advances in network management automation and Software-Defined Networking (SDN) are easing network Policy management tasks. At the same time, these new technologies create a new mode of failure in the management cycle itself. Network policies are presented in an abstract model at a centralized controller and deployed as low-level rules across network devices. Thus, any software and hardware element in that cycle can be a potential cause of underlying network problems. In this paper, we present and solve a network Policy fault localization problem that arises in operating Policy management frameworks for a production network. We formulate our problem via risk modeling and propose a greedy algorithm that quickly localizes faulty Policy objects in the network Policy. We then design and develop SCOUT---a fully-automated system that produces faulty Policy objects and further pinpoints physical-level failures which made the objects faulty. Evaluation results using a real testbed and extensive simulations demonstrate that SCOUT detects faulty objects with small false positives and false negatives.