PSI: Precise Security Instrumentation for Enterprise Networks
Tianlong Yu, Seyed Kaveh Fayaz, Michael P. Collins, Vyas Sekar, Srinivasan Seshan
摘要
Despite soaring investments in IT infrastructure, the state of operational network security continues to be abysmal. We argue that this is because existing enterprise security approaches fundamentally lack precision in one or more dimensions: (1) isolation to ensure that the enforcement mechanism does not induce interference across different principals; (2) context to customize policies for different devices; and (3) agility to rapidly change the security posture in response to events. To address these shortcomings, we present PSI, a new enterprise network security architecture that addresses these pain points. PSI enables fine-grained and dynamic security postures for different network devices. These are implemented in isolated enclaves and thus provides precise instrumentation on these above dimensions by construction. To this end, PSI leverages recent advances in software-defined networking (SDN) and network functions virtualization (NFV). We design expressive policy abstractions and scalable orchestration mechanisms to implement the security postures. We implement PSI using an industry-grade SDN controller (OpenDaylight) and integrate several commonly used enforcement tools (e.g., Snort, Bro, Squid). We show that PSI is scalable and is an enabler for new detection and prevention capabilities that would be difficult to realize with existing solutions. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Fine-Grained Isolation for Scalable, Dynamic, Multi-tenant Edge CloudsYuxin Ren, Guyue Liu, Vlad Nitu, Wenyuan Shao 等USENIX ATC 2020 · 被引用 47 次
- vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection SystemsHongda Li, Hongxin Hu, Guofei Gu, Gail-Joon Ahn 等CCS 2018 · 被引用 47 次
- P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPFOsama Bajaber, Bo Ji, Peng GaoS&P 2024 · 被引用 11 次
- SAD THUG: Structural Anomaly Detection for Transmissions of High-value Information Using GraphicsJonathan P. ChapmanUSENIX Security 2018 · 被引用 8 次
- SuperFE: A Scalable and Flexible Feature Extractor for ML-based Traffic Analysis ApplicationsMenghao Zhang, Guanyu Li, Cheng Guo, Renyu Yang 等EuroSys 2025 · 被引用 4 次
它引用的顶会 Paper2
- Enabling Practical Software-defined Networking Security Applications with OFXJohn Sonchack, Jonathan M. Smith, Adam J. Aviv, Eric KellerNDSS 2016 · 被引用 82 次
- Towards SDN-Defined Programmable BYOD (Bring Your Own Device) SecuritySungmin Hong, Robert Baykov, Lei Xu, Srinath Nadimpalli 等NDSS 2016 · 被引用 52 次
相关 Paper
- Programmable In-Network Security for Context-aware BYOD PoliciesQiao Kang, Lei Xue, Adam Morrison, Yuxin Tang 等USENIX Security 2020
- On the Safety and Efficiency of Virtual Firewall Elasticity ControlJuan Deng, Hongda Li, Hongxin Hu, Kuang-Ching Wang 等NDSS 2017
- SDN Application Backdoor: Disrupting the Service via Poisoning the TopologyShuhua Deng, Xian Qing, Xiaofan Li, Xing Gao 等INFOCOM 2023 · 被引用 8 次
- AIM-SDN: Attacking Information Mismanagement in SDN-datastoresVaibhav Hemant Dixit, Adam Doupé, Yan Shoshitaishvili, Ziming Zhao 等CCS 2018 · 被引用 31 次
- AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksSeungsoo Lee, Seungwon Woo, Jinwoo Kim, Vinod Yegneswaran 等INFOCOM 2020 · 被引用 13 次
