Design of the Multi-Level Security Network Switch System Which Restricts Covert Channel

Xiong Liu,Haiwei Xue,Xiaoping Feng,Yiqi Dai
DOI: https://doi.org/10.1109/iccsn.2011.6013582
2011-01-01
Abstract:The administrator shall implement multilevel security policy in a multilevel security network system. The policy must ensure the information flow from low level host to the same level host or high level host, and prevent the information flow from high level host to low level host, but traditional network is difficult to meet the requirement. This paper proposes a design of multi-level security network switch system. The design adds a module named Filter based on OpenFlow. OpenFlow can control the packets flow of the network, and the Filter can check the packet's content and delay the packets then restrict covert channel. Using OpenFlow and the Filter, the system can implement the multilevel security policy in the scenario of local area network. The experiment verified the feasibility of the design.
What problem does this paper attempt to address?