A Novel Software Defined Security Framework for SDN

被引:0
|
作者
Basu, Srijita [1 ]
Raun, Neha Firdaush [1 ]
Ghosal, Avishek [1 ]
Chatterjee, Debanjan [1 ]
Maitra, Debarghya [2 ]
Mazumdar, Chandan [1 ]
机构
[1] Jadavpur Univ, Ctr Distributed Comp, Kolkata, India
[2] Jadavpur Univ, Kolkata, India
关键词
Application; Controller; Firewall; Security;
D O I
10.1007/978-3-031-61231-2_14
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Security (SDS) entails the security implementation of a network, based on certain applications. It can be portrayed as a virtualized abstraction of the essential security features into a single software layer. SDS can be designed for traditional physical, virtualized, NFVs (Network Function Virtualization) and SDN (Software Defined Networking) based networks. This paper aims at developing an SDS framework for ONOS based SDN systems. Though most of the existing controllers like RYU, Floodlight, POX and ODL provide a framework for designing SDN applications and REST APIs, ONOS (Open Network Operating System) is comparatively more flexible. The novelty in considering the "SDS on SDN" design lies in the uniformity and scalability of the system. Moreover, a data plane device can now act in a polymorphic manner. The required security rules are provided into the SDS framework that in turn modifies the corresponding flow rules and the control plane forwards the same to the dataplane devices. Thus, a data plane device can have the functionalities of a firewall, IDS, IPS, AAA, etc. depending upon the triggered flow rule. Dependency on a particular security appliance orVNFand the necessity of maintaining multiple instances of the same is eliminated in the proposed system. The experimental setup comprises of a hybrid network topology of virtual mininet switches and HP Aruba switches. The performance analysis of the system in terms of throughput, bandwidth, and RTT latency shows a considerably low overhead thereby proving the effectiveness of the scheme.
引用
收藏
页码:216 / 230
页数:15
相关论文
共 50 条
  • [1] Security Analysis as Software-defined Security for SDN Environment
    El Moussaid, Nadya
    Toumanari, Ahmed
    El Azhari, Maryam
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 87 - 92
  • [2] On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter
    Sallam, Ahmed
    Refaey, Ahmed
    Shami, Abdallah
    [J]. IEEE ACCESS, 2019, 7 : 146577 - 146587
  • [3] Software Defined Networking (SDN) and its Security Issues
    Aziz, Normaziah A.
    Mantoro, Teddy
    Khairudin, M. Aiman
    Murshid, A. Faiz B. A.
    [J]. 2018 4TH INTERNATIONAL CONFERENCE ON COMPUTING, ENGINEERING, AND DESIGN (ICCED 2018), 2018, : 40 - 45
  • [4] A software defined security scheme based on SDN environment
    Xu, Xiaolong
    Hu, Liuyun
    [J]. 2017 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC), 2017, : 504 - 512
  • [5] A Recent Trends in Software Defined Networking (SDN) Security
    Saxena, Mudit
    Kumar, Rakesh
    [J]. PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 851 - 855
  • [6] Software-Defined Networking (SDN): the security review
    Hussein, A.
    Chadad, Louma
    Adalian, Nareg
    Chehab, Ali
    Elhajj, Imad H.
    Kayssi, Ayman
    [J]. Journal of Cyber Security Technology, 2020, 4 (01) : 1 - 66
  • [7] Software Defined IoT Security Framework
    Salman, Ola
    Elhajj, Imad
    Chehab, Ali
    Kayssi, Ayman
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 75 - 80
  • [8] Enhancing Network Security through Software Defined Networking (SDN)
    Shin, Seungwon
    Xu, Lei
    Hong, Sungmin
    Gu, Guofei
    [J]. 2016 25TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN), 2016,
  • [9] "Common Criteria" and Software-Defined Network (SDN) Security
    Mukhanov, A.
    Petukhov, A.
    Pilugin, P.
    [J]. 2018 INTERNATIONAL SCIENTIFIC AND TECHNICAL CONFERENCE MODERN COMPUTER NETWORK TECHNOLOGIES (MONETEC 2018), 2018,
  • [10] Security Enhancement in Software Defined Networking (SDN): A Threat Model
    Sharma, Pradeep Kumar
    Tyagi, S. S.
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (09) : 208 - 217