ASTRAEA: Towards an effective and usable application permission system for SDN

被引:5
|
作者
Kang, Heedo [1 ]
Yoon, Changhoon [1 ]
Shin, Seungwon [1 ]
机构
[1] Korea Adv Inst Sci & Technol, 291 Daehak Ro, Daejeon, South Korea
关键词
Software-defined networking security; Permission system;
D O I
10.1016/j.comnet.2019.03.007
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Today, Software-defined networking (SDN), which decouples the control plane from the data plane, has quickly emerged as a new promising networking architecture. In SDN, a centralized control plane (a.k.a., SDN controller) manages the entire network; hence, the security of this control plane has become increasingly important. One of the critical security issues, recently raised, is that an SDN application can unrestrictedly access SDN resources, manipulate the operations of an SDN controller, and finally destroy the network. To address this issue, researchers have proposed permission-based access control models for an SDN controller, and well-known SDN controllers have recently started employing these ideas. However, permission-based access control mechanisms can be evaded by excessively/insufficiently privileged applications (i.e., permission gap), and SDN controllers employing such mechanisms are no exception. In addition, it is possible that the permissions required for an application are not clearly presented to an administrator (i.e., semantic gap). Since an SDN controller directly manages a network, the damage caused by this problem would be much more serious. To address this issue, in this paper, we introduce a novel and usable security mechanism called ASTRAEA that can effectively help SDN operators avoid such potentially dangerous SDN applications. (C) 2019 Published by Elsevier.B.V.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [21] Research and Application of Remote Operating Permission Security Control System of Protection Information Master Station
    Liu M.
    Tang Z.
    Cao X.
    Hu S.
    Dianwang Jishu/Power System Technology, 2022, 46 (01): : 412 - 419
  • [22] Organ donor research: towards a more effective system
    不详
    LANCET, 2017, 390 (10106): : 1928 - 1928
  • [23] Towards an Effective Arousal Detection System for Virtual Reality
    Mavridou, Ifigeneia
    Seiss, Ellen
    Kostoulas, Theodoros
    Nduka, Charles
    Balaguer-Ballester, Emili
    PROCEEDINGS OF THE WORKSHOP ON HUMAN-HABITAT FOR HEALTH (H3'18): HUMAN-HABITAT MULTIMODAL INTERACTION FOR PROMOTING HEALTH AND WELL-BEING IN THE INTERNET OF THINGS ERA, 2018,
  • [24] TOWARDS AN EFFECTIVE ON-LINE REFERENCE RETRIEVAL SYSTEM
    NEGUS, AE
    HALL, JL
    INFORMATION STORAGE AND RETRIEVAL, 1971, 7 (06): : 249 - &
  • [25] Towards an impartial and effective corporate governance rating system
    Donker, Han
    Zahir, Saif
    CORPORATE GOVERNANCE-THE INTERNATIONAL JOURNAL OF BUSINESS IN SOCIETY, 2008, 8 (01): : 83 - +
  • [26] S5: An Application Sensitive QoS Assurance System via SDN
    Wang, Lei
    Li, Qing
    Liu, Lu
    Jiang, Yong
    Xu, Mingwei
    Wu, Jianping
    2018 IEEE 37TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2018,
  • [27] Application Identification System for SDN QoS based on Machine Learning and DNS Responses
    Huang, Nen-Fu
    Li, Che-Chuan
    Li, Chi-Hsuan
    Chen, Chia-Chi
    Chen, Ching-Hsuan
    Hsu, I-Hsien
    2017 19TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS 2017): MANAGING A WORLD OF THINGS, 2017, : 407 - 410
  • [28] Research on System Application of Network Wireless Transmission Technology Based on Computer SDN
    Yang Jing
    Deng Xiaolong
    2023 3RD ASIA-PACIFIC CONFERENCE ON COMMUNICATIONS TECHNOLOGY AND COMPUTER SCIENCE, ACCTCS, 2023, : 194 - 198
  • [29] An Effective Lightweight Intrusion Detection System with Blockchain to Mitigate Attacks in SDN/NFV Enabled Cloud
    Abdulqadder, Ihsan H.
    Zhou, Shijie
    Aziz, Israa T.
    Zou, Deqing
    Deng, Xianjun
    Akber, Syed Muhammad Abrar
    2021 6TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2021,
  • [30] A NOVEL SYSTEM FOR SAFE AND EFFECTIVE HERBICIDE APPLICATION
    DAWSON, R
    ROBINSON, T
    RIEU, AD
    RYAN, PJ
    BRIGHTON CROP PROTECTION CONFERENCE - WEEDS 1989, VOLS 1-3, 1989, : 657 - 662