ASTRAEA: Towards an effective and usable application permission system for SDN

被引:5
|
作者
Kang, Heedo [1 ]
Yoon, Changhoon [1 ]
Shin, Seungwon [1 ]
机构
[1] Korea Adv Inst Sci & Technol, 291 Daehak Ro, Daejeon, South Korea
关键词
Software-defined networking security; Permission system;
D O I
10.1016/j.comnet.2019.03.007
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Today, Software-defined networking (SDN), which decouples the control plane from the data plane, has quickly emerged as a new promising networking architecture. In SDN, a centralized control plane (a.k.a., SDN controller) manages the entire network; hence, the security of this control plane has become increasingly important. One of the critical security issues, recently raised, is that an SDN application can unrestrictedly access SDN resources, manipulate the operations of an SDN controller, and finally destroy the network. To address this issue, researchers have proposed permission-based access control models for an SDN controller, and well-known SDN controllers have recently started employing these ideas. However, permission-based access control mechanisms can be evaded by excessively/insufficiently privileged applications (i.e., permission gap), and SDN controllers employing such mechanisms are no exception. In addition, it is possible that the permissions required for an application are not clearly presented to an administrator (i.e., semantic gap). Since an SDN controller directly manages a network, the damage caused by this problem would be much more serious. To address this issue, in this paper, we introduce a novel and usable security mechanism called ASTRAEA that can effectively help SDN operators avoid such potentially dangerous SDN applications. (C) 2019 Published by Elsevier.B.V.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [1] Towards a Usable and an Efficient Elder Fall Detection System
    Daher, Mohamad
    El Najjar, Maan El Badaoui
    Diab, Ahmad
    Khalil, Mohamad
    Charpillet, Francois
    2015 INTERNATIONAL CONFERENCE ON ADVANCES IN BIOMEDICAL ENGINEERING (ICABME), 2015, : 93 - 96
  • [2] Towards SDN Network Proofs - taming a complex system
    Stevens, Matt
    Ng, Bryan
    Streader, David
    Welch, Ian
    2016 21ST INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS (ICECCS 2016), 2016, : 171 - 180
  • [3] Towards an SDN Network Control Application for Differentiated Traffic Routing
    Adami, Davide
    Antichi, Gianni
    Garroppo, Rosario G.
    Giordano, Stefano
    Moore, Andrew W.
    2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2015, : 5827 - 5832
  • [4] A STUDY ON APPLICATION-TOWARDS BANDWIDTH GUARANTEE BASED ON SDN
    Cao Shaohua
    Tong Mengzhu
    Lv, Zhihan
    Jiang, Dingde
    2016 IEEE GLOBECOM WORKSHOPS (GC WKSHPS), 2016,
  • [5] Towards a Usable Anomaly Diagnosis System among Internet Firewalls' Rules
    Chao, Chi-Shih
    Yang, Stephen J. H.
    JOURNAL OF INTERNET TECHNOLOGY, 2019, 20 (03): : 789 - 799
  • [6] Research on Application of SDN in Dispatching System of Power Grid
    Yan Zijian
    Zhu Guiying
    Liu Xiaomei
    Sun Peng
    PROCEEDINGS OF THE 2017 6TH INTERNATIONAL CONFERENCE ON ENERGY, ENVIRONMENT AND SUSTAINABLE DEVELOPMENT (ICEESD 2017), 2017, 129 : 1003 - 1010
  • [7] The architecture design and application of IP SDN controller system
    Zhu, Chuanming
    Chen, Huiguang
    Li, Jingwen
    2022 IEEE 6TH ADVANCED INFORMATION TECHNOLOGY, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (IAEAC), 2022, : 621 - 624
  • [9] Towards a system for business process design from re-usable library elements
    Keast, JE
    Roy, R
    Broughton, T
    ADVANCES IN MANUFACTURING TECHNOLOGY - XIII, 1999, : 383 - 387
  • [10] Towards SDN-based Fog Computing: MQTT Broker Virtualization for Effective and Reliable Delivery
    Xu, Yiming
    Mahendran, V.
    Radhakrishnan, Sridhar
    2016 8TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORKS (COMSNETS), 2016,