Requirement Analysis for Abstracting Security in Software Defined Network

被引:0
|
作者
Nehra, Ajay [1 ]
Tripathi, Meenakshi [1 ]
Gaur, M. S. [1 ]
机构
[1] Malaviya Natl Inst Technol, Dept Comp Sci & Engn, Jaipur, Rajasthan, India
关键词
SDN; Software Defined Network; Security; Language; Abstraction; Network Programming Languages; Domain Specific Languages;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Network(SDN) decouples the control plane from the data plane. The aim of this decoupling in SDN helps to create an open programmable network. Programmability offers the capability to write custom network modules i.e. topology discovery, switching, routing, traffic monitoring, access control, etc. Building SDN applications in the primary controller(i.e. Pox, Opendaylight, etc.) configuration is tedious due to low-level programming. The programmability in SDN not only allows flexibility in network management but also introduce new security holes. Indeed the researchers have proposed several abstractions for network management, but we believe the similar abstractions for security is needed to realize the holistic view of SDN fully. In this paper, we review the existing programming model and available abstractions for SDN and show the need for a new security abstraction through an example. We determine that existing abstractions lack the expressiveness for security measures precisely. So there is a need for abstractions which can express the threat detection, mitigation or even prevention by analyzing huge number of logs and can classify them into groups based on their intent.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] An Experimental Software Defined Security Controller for Software Defined Network
    Al-Zewairi, Malek
    Suleiman, Dima
    Almajali, Sufyan
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 32 - 36
  • [2] A ZigBee Software Defined Network Security
    Basabi, Alireza Ebrahimi
    He, Jingsha
    Hashemi, Seyed Mahmood
    Xuan, Xinggang
    Pathan, Muhammad Salman
    Zardari, Zulfiqar Ali
    [J]. International Journal of Network Security, 2022, 24 (01) : 11 - 19
  • [3] Abstracting network state in Software Defined Networks (SDN) for rendezvous services
    Gurbani, Vijay K.
    Scharf, Michael
    Lakshman, T. V.
    Hilt, Volker
    Marocco, Enrico
    [J]. 2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012, : 6627 - 6632
  • [4] Security Analysis of Software Defined Wireless Network Monitoring with sFlow and FlowVisor
    Swapna, Asma Islam
    Reza, Md Rezaul Huda
    Aion, Mainul Kabir
    [J]. PROCEEDINGS OF THE 2016 INTERNATIONAL CONFERENCE ON COMMUNICATION AND ELECTRONICS SYSTEMS (ICCES), 2016, : 67 - 73
  • [5] Design and analysis of a robust security layer for software defined network framework
    Alhaj, Ali Nadim
    Patel, Narottam Das
    Singh, Ajeet
    Bondugula, Rohit Kumar
    Dar, Mohsin Furkh
    Ahamed, Jameel
    [J]. INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2024, 46 (01)
  • [6] Security Challenges in Software Defined Network and their Solutions
    Patil, Varsha
    Patil, Charulata
    Awale, R. N.
    [J]. 2017 8TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2017,
  • [7] Exploring the Security of Software Defined Network Controllers
    Kaur, Prabhjot
    Patel, Shiv
    Mittal, Sanjana
    Sharma, Surbhi
    Butakov, Sergey
    [J]. INFORMATICS AND INTELLIGENT APPLICATIONS, 2022, 1547 : 165 - 178
  • [8] Ameliorate Security by Introducing Security Server in Software Defined Network
    Vijila, J.
    Raj, A. Albert
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 62 (03): : 1077 - 1096
  • [9] Software-Defined Network Security over OpenStack Clouds: A Systematic Analysis
    Lane, Nicolas P.
    Koslovski, Guilherme P.
    Pillon, Mauricio A.
    Miers, Charles C.
    Gonzalez, Nelson M.
    [J]. PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE (CLOSER), 2020, : 423 - 429
  • [10] An Analysis for Understanding Software Security Requirement Methodologies
    Du, Jing
    Yang, Ye
    Wang, Qing
    [J]. 2009 THIRD IEEE INTERNATIONAL CONFERENCE ON SECURE SOFTWARE INTEGRATION AND RELIABILITY IMPROVEMENT, PROCEEDINGS, 2009, : 141 - 149