A Security Evaluation Framework for Software-Defined Network Architectures in Data Center Environments

被引:0
|
作者
Ivkic, Igor [1 ,2 ]
Thiede, Dominik [2 ]
Race, Nicholas [1 ]
Broadbent, Matthew [3 ]
Gouglidis, Antonios [1 ]
机构
[1] Univ Lancaster, Lancaster, England
[2] Univ Appl Sci Burgenland, Eisenstadt, Austria
[3] Edinburgh Napier Univ, Edinburgh, Midlothian, Scotland
关键词
Network Security; Data Center Architecture; Software-Defined Networks; Security Evaluation Framework;
D O I
10.5220/0011988300003488
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The importance of cloud computing has grown over the last years, which resulted in a significant increase of Data Center (DC) network requirements. Virtualisation is one of the key drivers of that transformation and enables a massive deployment of computing resources, which exhausts server capacity limits. Furthermore, the increased network endpoints need to be handled dynamically and centrally to facilitate cloud computing functionalities. Traditional DCs barely satisfy those demands because of their inherent limitations based on the network topology. Software-Defined Networks (SDN) promise to meet the increasing network requirements for cloud applications by decoupling control functionalities from data forwarding. Although SDN solutions add more flexibility to DC networks, they also pose new vulnerabilities with a high impact due to the centralised architecture. In this paper we propose an evaluation framework for assessing the security level of SDN architectures in four different stages. Furthermore, we show in an experimental study, how the framework can be used for mapping SDN threats with associated vulnerabilities and necessary mitigations in conjunction with risk and impact classification. The proposed framework helps administrators to evaluate the network security level, to apply countermeasures for identified SDN threats, and to meet the networks security requirements.
引用
收藏
页码:277 / 288
页数:12
相关论文
共 50 条
  • [1] SODA: A software-defined security framework for IoT environments
    Kim, Yeonkeun
    Nam, Jaehyun
    Park, Taejune
    Scott-Hayward, Sandra
    Shin, Seungwon
    [J]. COMPUTER NETWORKS, 2019, 163
  • [2] Development of Network Security Models in the Software-defined Infrastructure of Virtual Data Center
    Bolodurina, Irina P.
    Parfenov, Denis I.
    [J]. PROCEEDINGS OF THE 2018 IEEE CONFERENCE OF RUSSIAN YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING (EICONRUS), 2018, : 16 - 20
  • [3] Software-Defined Data Center
    Ghazanfar Ali
    Jie Hu
    Bhumip Khasnabish
    [J]. ZTE Communications, 2013, 11 (04) : 2 - 7
  • [4] Performance Evaluation of Software-Defined Networking Architectures Using Network Calculus
    Zerrik, S.
    El Ouadghiri, D.
    Bakhouya, M.
    [J]. PROCEEDINGS OF 2016 5TH INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS (ICMCS), 2016, : 543 - 547
  • [5] Power-Efficient Software-Defined Data Center Network
    Zhao, Yong
    Wang, Xingwei
    He, Qiang
    Yi, Bo
    Huang, Min
    Cheng, Wenlin
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (12): : 10018 - 10033
  • [6] SDSA: A Framework of a Software-Defined Security Architecture
    Liu Yanbing
    Lu Xingyu
    Jian Yi
    Xiao Yunpeng
    [J]. CHINA COMMUNICATIONS, 2016, 13 (02) : 178 - 188
  • [7] Building the Software-Defined Data Center
    Shabanov, B. M.
    Samovarov, O., I
    [J]. PROGRAMMING AND COMPUTER SOFTWARE, 2019, 45 (08) : 458 - 466
  • [8] Building the Software-Defined Data Center
    B. M. Shabanov
    O. I. Samovarov
    [J]. Programming and Computer Software, 2019, 45 : 458 - 466
  • [9] A Tensor-Based Framework for Software-Defined Cloud Data Center
    Kuang, Liwei
    Yang, Laurence T.
    Rho, Seungmin
    Yan, Zheng
    Qiu, Kai
    [J]. ACM TRANSACTIONS ON MULTIMEDIA COMPUTING COMMUNICATIONS AND APPLICATIONS, 2016, 12 (05)
  • [10] Security Features in a Hybrid Software-Defined Network
    Fosic, Igor
    Zagar, Drago
    [J]. TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2021, 28 (04): : 1371 - 1379