Safeguard: Security Controls at the Software Defined Network Layer

๐Ÿ“… 2026-01-24
๐Ÿ“ˆ Citations: 2
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
This work addresses the vulnerability of data-driven security policies in software-defined networks (SDNs) to overreacting to anomalous traffic, which can lead to misclassification and degrade the performance of machine learningโ€“based intrusion detection systems. To mitigate this issue, the authors propose Safeguard, a novel mechanism that introduces a set of allow rules derived from known benign traffic. These rules operate in conjunction with data-driven policies, enabling coordinated enforcement at the network edge to prevent unintended responses while simultaneously applying firewall rules against confirmed malicious traffic. By integrating this dual-layer approach, Safeguard effectively alleviates overblocking, significantly enhancing the robustness and accuracy of SDN security policies. Experimental evaluation through a prototype implementation demonstrates the efficacy of the proposed mechanism in dynamic SDN environments.

Technology Category

Natural Language Processing: Safety and RobustnessMachine Learning: Hardware-aware MLApplication Domains: Security

Application Category

Security and Privacy: Large-scale security measurementsResponsible Web: Machine-in-the-loop, human agency and autonomySystems and Infrastructure for Web, Mobile and WoT: Applied ML and AI for Web-based mobile applications
๐Ÿ“ Abstract
Improvements in software defined networking allow for policy to be informed and modified by data-driven applications that can adjust policy to accommodate fluctuating requirements at line speed. However, there is some concern that over-correction can occur and cause unintended consequences depending on the data received. This is particularly problematic for network security features, such as machine-learning intrusion detection systems. We present Safeguard, a rule-based policy that overlaps a data-driven policy to prevent unintended responses for edge cases in network traffic. We develop a reference implementation of a network traffic classifier that enforces firewall rules for malicious traffic, and show how additional rulesets to allow known-good traffic are essential in utilizing a data-driven network policy.
Problem

Research questions and friction points this paper is trying to address.

Software Defined Networking
Network Security
Data-driven Policy
Intrusion Detection
Over-correction
Innovation

Methods, ideas, or system contributions that make the work stand out.

Software Defined Networking
Data-driven Policy
Rule-based Safeguard
Intrusion Detection
Network Security
๐Ÿ”Ž Similar Papers
No similar papers found.
Y
Yi Lyu
University of Wisconsin-Madison
S
Shichun Yu
University of Wisconsin-Madison
J
Joe Catudal
University of Wisconsin-Madison