Ahmad, Liyanage, Shahabuddin, Ylianttila, and Gurtov
92
Remediate, Recover, Diagnose and Refine (D
2
R
2
+DR) [26]. Through global visibility
and a cycle of harvesting intelligence from the underlying network, the SDN control
plane stays updated of the network situation. With programmable APIs in network
equipment, fast reaction to failures in network equipment and miss‐configuration is
achieved. SDN‐based resilience frameworks are developed that provide policy‐
controlled management with policy‐based network configuration according to resilience strategies. An OpenFlow application is presented in [27] to enable interaction
between multiple resilience mechanisms. The framework described in [27] also
enables translation of high‐level policies to device level configuration to act promptly
to various failures. Other approaches include using multiple controllers to increase
resilience of the SDNs.
4.4.6 Security Systems and Firewalls
To explain the possibilities of anomalies due to applications, consider the already
existing example. Cellular network applications and middleboxes are independently
managed by cellular operators and application developers. Application developers are
unaware of the middlebox policies enforced by the operators. The operators have less
knowledge of the application behavior and requirements. Such a mismatch or lack of
understanding can create potential security challenges. For example, an operator can
set an aggressive timeout value to quickly release the resources occupied by inactive
TCP connections in the firewall. This could cause frequent disruptions in important
application sessions [28].
Normally traffic is routed to various middleboxes to perform network security
evaluation or check the traffic behavior and legality. However, the traditional middleboxes have a number of challenges regarding its placement, scalability and security
policy alteration. These challenges mostly occur due to complex manual configurations,
the need of path‐specific middlebox placement, and non‐flexibility of the existing
network architectures [29]. SDN makes the deployment of middleboxes simple and
elegant through network programmability and centralized network control. In [30], it is
proposed to integrate the processing of middleboxes into the network itself, by using
the concepts of SDN for policy consistency and higher visibility of the behavior of
middleboxes through a centralized control. The simplicity of deploying and managing
diverse and complex middleboxes, due to the above‐mentioned characteristics of
SDN, is presented in [31].
4.4.7 Network Security Automation
Automation is the process of minimizing human‐machine interaction by delegating
complex control functions to machines for reliability and accuracy. The main purpose
of machine execution of complex functions, called automation, is accuracy and reliability
through:
i) information acquisition;
ii) information analysis;
iii) decision and action selection; and
iv) action implementation [37].
92
Remediate, Recover, Diagnose and Refine (D
2
R
2
+DR) [26]. Through global visibility
and a cycle of harvesting intelligence from the underlying network, the SDN control
plane stays updated of the network situation. With programmable APIs in network
equipment, fast reaction to failures in network equipment and miss‐configuration is
achieved. SDN‐based resilience frameworks are developed that provide policy‐
controlled management with policy‐based network configuration according to resilience strategies. An OpenFlow application is presented in [27] to enable interaction
between multiple resilience mechanisms. The framework described in [27] also
enables translation of high‐level policies to device level configuration to act promptly
to various failures. Other approaches include using multiple controllers to increase
resilience of the SDNs.
4.4.6 Security Systems and Firewalls
To explain the possibilities of anomalies due to applications, consider the already
existing example. Cellular network applications and middleboxes are independently
managed by cellular operators and application developers. Application developers are
unaware of the middlebox policies enforced by the operators. The operators have less
knowledge of the application behavior and requirements. Such a mismatch or lack of
understanding can create potential security challenges. For example, an operator can
set an aggressive timeout value to quickly release the resources occupied by inactive
TCP connections in the firewall. This could cause frequent disruptions in important
application sessions [28].
Normally traffic is routed to various middleboxes to perform network security
evaluation or check the traffic behavior and legality. However, the traditional middleboxes have a number of challenges regarding its placement, scalability and security
policy alteration. These challenges mostly occur due to complex manual configurations,
the need of path‐specific middlebox placement, and non‐flexibility of the existing
network architectures [29]. SDN makes the deployment of middleboxes simple and
elegant through network programmability and centralized network control. In [30], it is
proposed to integrate the processing of middleboxes into the network itself, by using
the concepts of SDN for policy consistency and higher visibility of the behavior of
middleboxes through a centralized control. The simplicity of deploying and managing
diverse and complex middleboxes, due to the above‐mentioned characteristics of
SDN, is presented in [31].
4.4.7 Network Security Automation
Automation is the process of minimizing human‐machine interaction by delegating
complex control functions to machines for reliability and accuracy. The main purpose
of machine execution of complex functions, called automation, is accuracy and reliability
through:
i) information acquisition;
ii) information analysis;
iii) decision and action selection; and
iv) action implementation [37].
