A Novel Software Defined Security Framework for SDN

被引:0
|
作者
Basu, Srijita [1 ]
Raun, Neha Firdaush [1 ]
Ghosal, Avishek [1 ]
Chatterjee, Debanjan [1 ]
Maitra, Debarghya [2 ]
Mazumdar, Chandan [1 ]
机构
[1] Jadavpur Univ, Ctr Distributed Comp, Kolkata, India
[2] Jadavpur Univ, Kolkata, India
关键词
Application; Controller; Firewall; Security;
D O I
10.1007/978-3-031-61231-2_14
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Security (SDS) entails the security implementation of a network, based on certain applications. It can be portrayed as a virtualized abstraction of the essential security features into a single software layer. SDS can be designed for traditional physical, virtualized, NFVs (Network Function Virtualization) and SDN (Software Defined Networking) based networks. This paper aims at developing an SDS framework for ONOS based SDN systems. Though most of the existing controllers like RYU, Floodlight, POX and ODL provide a framework for designing SDN applications and REST APIs, ONOS (Open Network Operating System) is comparatively more flexible. The novelty in considering the "SDS on SDN" design lies in the uniformity and scalability of the system. Moreover, a data plane device can now act in a polymorphic manner. The required security rules are provided into the SDS framework that in turn modifies the corresponding flow rules and the control plane forwards the same to the dataplane devices. Thus, a data plane device can have the functionalities of a firewall, IDS, IPS, AAA, etc. depending upon the triggered flow rule. Dependency on a particular security appliance orVNFand the necessity of maintaining multiple instances of the same is eliminated in the proposed system. The experimental setup comprises of a hybrid network topology of virtual mininet switches and HP Aruba switches. The performance analysis of the system in terms of throughput, bandwidth, and RTT latency shows a considerably low overhead thereby proving the effectiveness of the scheme.
引用
收藏
页码:216 / 230
页数:15
相关论文
共 50 条
  • [21] A trust management framework for Software Defined Network (SDN) controller and network applications
    Aliyu, Aliyu Lawal
    Aneiba, Adel
    Patwary, Mohammad
    Bull, Peter
    [J]. COMPUTER NETWORKS, 2020, 181
  • [22] DELTA: A Security Assessment Framework for Software-Defined Networks
    Lee, Seungsoo
    Yoon, Changhoon
    Lee, Chanhee
    Shin, Seungwon
    Yegneswaran, Vinod
    Porras, Phillip
    [J]. 24TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2017), 2017,
  • [23] A Framework for Security Services based on Software-Defined Networking
    Jeong, Jaehoon
    Seo, Jihyeok
    Cho, Geumhwan
    Kim, Hyoungshick
    Park, Jung-Soo
    [J]. 2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 150 - 153
  • [24] A comprehensive security assessment framework for software-defined networks
    Lee, Seungsoo
    Kim, Jinwoo
    Woo, Seungwon
    Yoon, Changhoon
    Scott-Hayward, Sandra
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    [J]. COMPUTERS & SECURITY, 2020, 91
  • [25] Software Defined Security Service Provisioning Framework for Internet of Things
    Khan, Faraz Idris
    Hameed, Sufian
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (12) : 411 - 425
  • [26] A Deep Learning Framework to Enhance Software Defined Networks Security
    Dawoud, Ahmed
    Shahristani, Seyed
    Raun, Chun
    [J]. 2018 32ND INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS (WAINA), 2018, : 709 - 714
  • [27] Demo: The Design and Implementation of Intelligent Software Defined Security Framework
    Zhang, Shasha
    Song, Shuyu
    Yang, Fan
    Li, Rongpeng
    Zhao, Zhifeng
    Zhang, Honggang
    [J]. MOBICOM'19: PROCEEDINGS OF THE 25TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING, 2019,
  • [28] SDProber: A Software Defined Prober for SDN
    Ramanathan, Sivaramakrishnan
    Kanza, Yaron
    Krishnamurthy, Balachander
    [J]. PROCEEDINGS OF THE SYMPOSIUM ON SDN RESEARCH (SOSR'18), 2018,
  • [29] SODA: A software-defined security framework for IoT environments
    Kim, Yeonkeun
    Nam, Jaehyun
    Park, Taejune
    Scott-Hayward, Sandra
    Shin, Seungwon
    [J]. COMPUTER NETWORKS, 2019, 163
  • [30] Multilevel Security Framework for NFV Based on Software Defined Perimeter
    Singh, Jaspreet
    Refaey, Ahmed
    Shami, Abdallah
    [J]. IEEE NETWORK, 2020, 34 (05): : 114 - 119