PSI: Precise Security Instrumentation for Enterprise Networks
Tianlong Yu, Seyed Kaveh Fayaz, Michael P. Collins, Vyas Sekar, Srinivasan Seshan
Abstract
Despite soaring investments in IT infrastructure, the state of operational network security continues to be abysmal. We argue that this is because existing enterprise security approaches fundamentally lack precision in one or more dimensions: (1) isolation to ensure that the enforcement mechanism does not induce interference across different principals; (2) context to customize policies for different devices; and (3) agility to rapidly change the security posture in response to events. To address these shortcomings, we present PSI, a new enterprise network security architecture that addresses these pain points. PSI enables fine-grained and dynamic security postures for different network devices. These are implemented in isolated enclaves and thus provides precise instrumentation on these above dimensions by construction. To this end, PSI leverages recent advances in software-defined networking (SDN) and network functions virtualization (NFV). We design expressive policy abstractions and scalable orchestration mechanisms to implement the security postures. We implement PSI using an industry-grade SDN controller (OpenDaylight) and integrate several commonly used enforcement tools (e.g., Snort, Bro, Squid). We show that PSI is scalable and is an enabler for new detection and prevention capabilities that would be difficult to realize with existing solutions. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b7b3ba5e-24ee-43bc-9002-172e0b745da8Cited by top-tier papers9
- Fine-Grained Isolation for Scalable, Dynamic, Multi-tenant Edge CloudsYuxin Ren, Guyue Liu, Vlad Nitu, Wenyuan Shao et al.USENIX ATC 2020 · 47 citations
- vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection SystemsHongda Li, Hongxin Hu, Guofei Gu, Gail-Joon Ahn et al.CCS 2018 · 47 citations
- P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPFOsama Bajaber, Bo Ji, Peng GaoS&P 2024 · 11 citations
- SAD THUG: Structural Anomaly Detection for Transmissions of High-value Information Using GraphicsJonathan P. ChapmanUSENIX Security 2018 · 8 citations
- SuperFE: A Scalable and Flexible Feature Extractor for ML-based Traffic Analysis ApplicationsMenghao Zhang, Guanyu Li, Cheng Guo, Renyu Yang et al.EuroSys 2025 · 4 citations
Builds on2
- Enabling Practical Software-defined Networking Security Applications with OFXJohn Sonchack, Jonathan M. Smith, Adam J. Aviv, Eric KellerNDSS 2016 · 82 citations
- Towards SDN-Defined Programmable BYOD (Bring Your Own Device) SecuritySungmin Hong, Robert Baykov, Lei Xu, Srinath Nadimpalli et al.NDSS 2016 · 52 citations
Related papers
- Programmable In-Network Security for Context-aware BYOD PoliciesQiao Kang, Lei Xue, Adam Morrison, Yuxin Tang et al.USENIX Security 2020
- On the Safety and Efficiency of Virtual Firewall Elasticity ControlJuan Deng, Hongda Li, Hongxin Hu, Kuang-Ching Wang et al.NDSS 2017
- SDN Application Backdoor: Disrupting the Service via Poisoning the TopologyShuhua Deng, Xian Qing, Xiaofan Li, Xing Gao et al.INFOCOM 2023 · 8 citations
- AIM-SDN: Attacking Information Mismanagement in SDN-datastoresVaibhav Hemant Dixit, Adam Doupé, Yan Shoshitaishvili, Ziming Zhao et al.CCS 2018 · 31 citations
- AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksSeungsoo Lee, Seungwon Woo, Jinwoo Kim, Vinod Yegneswaran et al.INFOCOM 2020 · 13 citations
