A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities

被引:0
|
作者
Cil, Altug [1 ,2 ]
Demirci, Mehmet [1 ,3 ]
机构
[1] Gazi Univ, Inst Informat, TR-06680 Ankara, Turkiye
[2] Sci & Technol Res Council Turkey TUBITAK, TR-06500 Ankara, Turkiye
[3] Gazi Univ, Fac Engn, Dept Comp Engn, TR-06570 Ankara, Turkiye
关键词
Computer Networks; Cyber Security; Forensics; Software- Defined Networks; OpenFlow; Southbound Interface; Ryu; ONOS; OpenDaylight; POX;
D O I
10.14744/sigma.2022.00107
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The proliferation of software-defined networks (SDN) increases the necessity of security and forensic research in this field. Network forensics is of particular importance considering the ever-increasing traffic density and variety of devices, and SDN has great potential for improved forensic processes thanks to its ability to provide a centralized view and control of the network. This article's motivation is the lack of a standard forensic process in SDN. The main objective of this study is to examine the differences in the forensic processes of different SDN controllers, whether the southbound interface data is sufficient for the forensic processes, and whether it is possible to choose the best controller in terms of forensics. Four of the most widely used controllers have been selected and tested under seven different scenarios to observe how the results were obtained in terms of forensics. During the tests, in addition to the routine data accesses, attack preparation tools and denial-of-service attack tools were used to expand the scope. Experiments in which each scenario was applied for four different controllers demonstrated that different controllers have different characteristics in network forensics parameters, such as attack type detection, attacker information, service interruptions, packet size, and the number of packets. Experiments proved that southbound interface data is sufficient for forensic processes, different controllers have different characteristics in forensic processes, none of the most used controllers is the best to cover all forensic processes, and a standard forensic method is required for software-defined network forensics.
引用
收藏
页码:425 / 437
页数:13
相关论文
共 50 条
  • [1] Determination of Network Forensics Process Requirements and Analysis in Software-Defined Networks
    Cil, Altug
    Demirci, Mehmet
    [J]. JOURNAL OF POLYTECHNIC-POLITEKNIK DERGISI, 2024, 27 (02):
  • [2] MARC: On Modeling and Analysis of Software-Defined Radio Access Network Controllers
    Papa, Arled
    Durner, Raphael
    Goshi, Endri
    Goratti, Leonardo
    Rasheed, Tinku
    Blenk, Andreas
    Kellerer, Wolfgang
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (04): : 4602 - 4615
  • [3] Algorithm to Balance Load of Controllers in Software-Defined Network
    Srisamarn, Ukrist
    Kitsuwan, Nattapong
    Pradittasnee, Lapas
    [J]. ISCIT 2019: PROCEEDINGS OF 2019 19TH INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES (ISCIT), 2019, : 282 - 287
  • [4] Comparative Analysis of Software Defined Networking (SDN) Controllers - In Terms of Traffic Handling Capabilities
    Rastogi, Abhishek
    Bais, Abdul
    [J]. PROCEEDINGS OF THE 2016 19TH INTERNATIONAL MULTI-TOPIC CONFERENCE (INMIC), 2016, : 137 - 142
  • [5] An adaptive load balancing scheme for software-defined network controllers
    Priyadarsini, Madhukrishna
    Mukherjee, Joy Chandra
    Bera, Padmalochan
    Kumar, Shailesh
    Jakaria, A. N. M.
    Rahman, M. Ashiqur
    [J]. COMPUTER NETWORKS, 2019, 164
  • [6] Denial-of-Service Prevention for Software-Defined Network Controllers
    Wolf, Tilman
    Li, Jingrui
    [J]. 2016 25TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN), 2016,
  • [7] Performance of Software-Defined Networking Controllers for Different Network Topologies
    Alrashedy, Kamel
    Kimmett, Ben
    Gulliver, T. Aaron
    [J]. 2017 IEEE PACIFIC RIM CONFERENCE ON COMMUNICATIONS, COMPUTERS AND SIGNAL PROCESSING (PACRIM), 2017,
  • [8] Software-Defined Network Forensics: Motivation, Potential Locations, Requirements, and Challenges
    Khan, Suleman
    Gani, Abdullah
    Wahab, Ainuddin Wahid Abdul
    Abdelaziz, Ahmed
    Ko, Kwangman
    Khan, Muhammad Khurram
    Guizani, Mohsen
    [J]. IEEE NETWORK, 2016, 30 (06): : 6 - 13
  • [9] A Comparative Study on Software-Defined Network with Traditional Networks
    Zoraida, Berty Smitha Evelin
    Indumathi, Ganesan
    [J]. TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2024, 13 (01): : 167 - 176
  • [10] Research on deployment strategy of multiple controllers in the software-defined satellite network
    Chen, Jintao
    Liang, Jun
    Guo, Zizhen
    Xiao, Nan
    Liu, Bo
    [J]. Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University, 2022, 49 (03): : 59 - 67