A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities

被引:0
|
作者
Cil, Altug [1 ,2 ]
Demirci, Mehmet [1 ,3 ]
机构
[1] Gazi Univ, Inst Informat, TR-06680 Ankara, Turkiye
[2] Sci & Technol Res Council Turkey TUBITAK, TR-06500 Ankara, Turkiye
[3] Gazi Univ, Fac Engn, Dept Comp Engn, TR-06570 Ankara, Turkiye
关键词
Computer Networks; Cyber Security; Forensics; Software- Defined Networks; OpenFlow; Southbound Interface; Ryu; ONOS; OpenDaylight; POX;
D O I
10.14744/sigma.2022.00107
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The proliferation of software-defined networks (SDN) increases the necessity of security and forensic research in this field. Network forensics is of particular importance considering the ever-increasing traffic density and variety of devices, and SDN has great potential for improved forensic processes thanks to its ability to provide a centralized view and control of the network. This article's motivation is the lack of a standard forensic process in SDN. The main objective of this study is to examine the differences in the forensic processes of different SDN controllers, whether the southbound interface data is sufficient for the forensic processes, and whether it is possible to choose the best controller in terms of forensics. Four of the most widely used controllers have been selected and tested under seven different scenarios to observe how the results were obtained in terms of forensics. During the tests, in addition to the routine data accesses, attack preparation tools and denial-of-service attack tools were used to expand the scope. Experiments in which each scenario was applied for four different controllers demonstrated that different controllers have different characteristics in network forensics parameters, such as attack type detection, attacker information, service interruptions, packet size, and the number of packets. Experiments proved that southbound interface data is sufficient for forensic processes, different controllers have different characteristics in forensic processes, none of the most used controllers is the best to cover all forensic processes, and a standard forensic method is required for software-defined network forensics.
引用
收藏
页码:425 / 437
页数:13
相关论文
共 50 条
  • [41] Orchestrating Network Functions in Software-Defined Networks
    Hu, Hongchao
    Pang, Lin
    Wang, Zhenpeng
    Cheng, Guozhen
    [J]. CHINA COMMUNICATIONS, 2017, 14 (02) : 104 - 117
  • [42] Software-defined Transport Network for Cloud Computing
    He, Jianfei
    [J]. 2013 OPTICAL FIBER COMMUNICATION CONFERENCE AND EXPOSITION AND THE NATIONAL FIBER OPTIC ENGINEERS CONFERENCE (OFC/NFOEC), 2013,
  • [43] FlowIdentity: Software-Defined Network Access Control
    Yakasai, Sadiq T.
    Guy, Chris G.
    [J]. 2015 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORK (NFV-SDN), 2015, : 115 - 120
  • [44] A Software-defined Network Based Lightweight Cluster
    Kara, Cavit
    Onur, Ertan
    [J]. 2018 26TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2018,
  • [45] Scalable Network Virtualization in Software-Defined Networks
    Drutskoy, Dmitry
    Keller, Eric
    Rexford, Jennifer
    [J]. IEEE INTERNET COMPUTING, 2013, 17 (02) : 20 - 27
  • [46] SDNForensics: A Comprehensive Forensics Framework for Software Defined Network
    Zhang, Shu-hui
    Meng, Xiang-xu
    Wang, Lian-hai
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND COMMUNICATION TECHNOLOGY (CNCT 2016), 2016, 54 : 92 - 99
  • [47] Software-Defined Fog Network Architecture for IoT
    Tomovic, Slavica
    Yoshigoe, Kenji
    Maljevic, Ivo
    Radusinovic, Igor
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2017, 92 (01) : 181 - 196
  • [48] An approach for deployment of BRS in software-defined network
    Dutta, Parinita
    Chatterjee, Rajeev
    Mandal, Jyotsna Kumar
    [J]. INNOVATIONS IN SYSTEMS AND SOFTWARE ENGINEERING, 2019, 15 (3-4) : 355 - 361
  • [49] A Review of Research on Software-Defined Optical Network
    Li Wei
    Yang Zhe
    Zhao Weihu
    Qi Zhengwei
    Liu Fei
    [J]. 2019 INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION, BIG DATA & SMART CITY (ICITBS), 2019, : 155 - 160
  • [50] Load balancing for software-defined network: a review
    Srivastava, Vivek
    Pandey, Ravi Shankar
    [J]. International Journal of Computers and Applications, 2022, 44 (08) : 746 - 759