A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities

被引:0
|
作者
Cil, Altug [1 ,2 ]
Demirci, Mehmet [1 ,3 ]
机构
[1] Gazi Univ, Inst Informat, TR-06680 Ankara, Turkiye
[2] Sci & Technol Res Council Turkey TUBITAK, TR-06500 Ankara, Turkiye
[3] Gazi Univ, Fac Engn, Dept Comp Engn, TR-06570 Ankara, Turkiye
关键词
Computer Networks; Cyber Security; Forensics; Software- Defined Networks; OpenFlow; Southbound Interface; Ryu; ONOS; OpenDaylight; POX;
D O I
10.14744/sigma.2022.00107
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The proliferation of software-defined networks (SDN) increases the necessity of security and forensic research in this field. Network forensics is of particular importance considering the ever-increasing traffic density and variety of devices, and SDN has great potential for improved forensic processes thanks to its ability to provide a centralized view and control of the network. This article's motivation is the lack of a standard forensic process in SDN. The main objective of this study is to examine the differences in the forensic processes of different SDN controllers, whether the southbound interface data is sufficient for the forensic processes, and whether it is possible to choose the best controller in terms of forensics. Four of the most widely used controllers have been selected and tested under seven different scenarios to observe how the results were obtained in terms of forensics. During the tests, in addition to the routine data accesses, attack preparation tools and denial-of-service attack tools were used to expand the scope. Experiments in which each scenario was applied for four different controllers demonstrated that different controllers have different characteristics in network forensics parameters, such as attack type detection, attacker information, service interruptions, packet size, and the number of packets. Experiments proved that southbound interface data is sufficient for forensic processes, different controllers have different characteristics in forensic processes, none of the most used controllers is the best to cover all forensic processes, and a standard forensic method is required for software-defined network forensics.
引用
收藏
页码:425 / 437
页数:13
相关论文
共 50 条
  • [31] Comparative Study of Software-Defined Networking (SDN) Traffic Controllers
    Pereira, Goncalo
    Silva, Jose
    Sousa, Pedro
    [J]. 2019 14TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2019,
  • [32] Experimental Performance Analysis of Software-Defined Network Switch and Controller
    Beshley, Mykola
    Panchenko, Oleksiy
    Seliuchenko, Marian
    Zyuzko, Oleg
    Kahalo, Ihor
    [J]. 2018 14TH INTERNATIONAL CONFERENCE ON ADVANCED TRENDS IN RADIOELECTRONICS, TELECOMMUNICATIONS AND COMPUTER ENGINEERING (TCSET), 2018, : 282 - 286
  • [33] On SDPN: Integrating the Software-Defined Perimeter (SDP) and the Software-Defined Network (SDN) Paradigms
    Lefebvre, Michael
    Engels, Daniel W.
    Nair, Suku
    [J]. 2022 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2022, : 353 - 358
  • [34] Efficient software-defined passive optical network with network coding
    Rentao Gu
    Shizong Zhang
    Yuefeng Ji
    Tonglu Guo
    Xiaoxiong Wang
    [J]. Photonic Network Communications, 2016, 31 : 239 - 250
  • [35] Optical Network Models and Their Application to Software-Defined Network Management
    Szyrkowiec, Thomas
    Autenrieth, Achim
    Kellerer, Wolfgang
    [J]. INTERNATIONAL JOURNAL OF OPTICS, 2017, 2017
  • [36] Efficient software-defined passive optical network with network coding
    Gu, Rentao
    Zhang, Shizong
    Ji, Yuefeng
    Guo, Tonglu
    Wang, Xiaoxiong
    [J]. PHOTONIC NETWORK COMMUNICATIONS, 2016, 31 (02) : 239 - 250
  • [37] Enhancing Network Performance Tomography in Software-Defined Cloud Network
    Zhang, Pengfei
    Zhao, Yusu
    Wang, Yongkun
    Jin, Yaohui
    [J]. IEEE COMMUNICATIONS LETTERS, 2023, 27 (03) : 832 - 835
  • [38] Performance Evaluation of Software Defined Network Controllers
    Canedo, Edna Dias
    Lopes de Mendonca, Fabio Lucio
    Amvame Nze, Georges Daniel
    Praciano, Bruno J. G.
    Pinheiro, Gabriel P. M.
    de Sousa, Rafael T., Jr.
    [J]. PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE (CLOSER), 2020, : 363 - 370
  • [39] Exploring the Security of Software Defined Network Controllers
    Kaur, Prabhjot
    Patel, Shiv
    Mittal, Sanjana
    Sharma, Surbhi
    Butakov, Sergey
    [J]. INFORMATICS AND INTELLIGENT APPLICATIONS, 2022, 1547 : 165 - 178
  • [40] Orchestrating Network Functions in Software-Defined Networks
    Hongchao Hu
    Lin Pang
    Zhenpeng Wang
    Guozhen Cheng
    [J]. China Communications, 2017, 14 (02) : 104 - 117