ASTRAEA: Towards an effective and usable application permission system for SDN

被引:5
|
作者
Kang, Heedo [1 ]
Yoon, Changhoon [1 ]
Shin, Seungwon [1 ]
机构
[1] Korea Adv Inst Sci & Technol, 291 Daehak Ro, Daejeon, South Korea
关键词
Software-defined networking security; Permission system;
D O I
10.1016/j.comnet.2019.03.007
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Today, Software-defined networking (SDN), which decouples the control plane from the data plane, has quickly emerged as a new promising networking architecture. In SDN, a centralized control plane (a.k.a., SDN controller) manages the entire network; hence, the security of this control plane has become increasingly important. One of the critical security issues, recently raised, is that an SDN application can unrestrictedly access SDN resources, manipulate the operations of an SDN controller, and finally destroy the network. To address this issue, researchers have proposed permission-based access control models for an SDN controller, and well-known SDN controllers have recently started employing these ideas. However, permission-based access control mechanisms can be evaded by excessively/insufficiently privileged applications (i.e., permission gap), and SDN controllers employing such mechanisms are no exception. In addition, it is possible that the permissions required for an application are not clearly presented to an administrator (i.e., semantic gap). Since an SDN controller directly manages a network, the damage caused by this problem would be much more serious. To address this issue, in this paper, we introduce a novel and usable security mechanism called ASTRAEA that can effectively help SDN operators avoid such potentially dangerous SDN applications. (C) 2019 Published by Elsevier.B.V.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [41] A Cost Effective Approach Towards Development Of A Smart Lighting System
    Purekar, Rohan
    Murali, Meera
    Joshi, Radhika
    2018 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION CONTROL AND AUTOMATION (ICCUBEA), 2018,
  • [42] EFFECTIVE PRICE APPLICATION IN PLANNED MANAGEMENT-SYSTEM
    KASAN, J
    POLITICKA EKONOMIE, 1978, 26 (02) : 121 - 125
  • [43] Towards a viable hydrogen storage system for transportation application
    Luo, W. (wluo@sandia.gov), 1600, Elsevier Ltd (404-406):
  • [44] Towards a viable hydrogen storage system for transportation application
    Luo, W
    Rönnebro, E
    JOURNAL OF ALLOYS AND COMPOUNDS, 2005, 404 : 392 - 395
  • [45] Towards an effective application of parameter estimation and uncertainty analysis to mathematical groundwater models
    Paulo A. Herrera
    Miguel Angel Marazuela
    Giovanni Formentin
    Thilo Hofmann
    SN Applied Sciences, 2022, 4
  • [46] Towards an effective I-DDQ test vector selection and application methodology
    vanSas, J
    Swerts, U
    Darquennes, M
    INTERNATIONAL TEST CONFERENCE 1996, PROCEEDINGS, 1996, : 491 - 500
  • [47] Towards an effective application of parameter estimation and uncertainty analysis to mathematical groundwater models
    Herrera, Paulo A.
    Marazuela, Miguel Angel
    Formentin, Giovanni
    Hofmann, Thilo
    SN APPLIED SCIENCES, 2022, 4 (08):
  • [48] Towards an improved and more cost effective health system for Australia - Reply
    Harper, RW
    MEDICAL JOURNAL OF AUSTRALIA, 1998, 169 (02) : 118 - 118
  • [49] TOWARDS AN EFFECTIVE SYSTEM OF FREE LEGAL AID IN MACEDONIA: PROBLEMS AND CHALLENGES
    Memetaj, Arlinda
    MIRDEC-9TH INTERNATIONAL ACADEMIC CONFERENCE MULTIDISCIPLINARY AND INDEPENDENT STUDIES ON SOCIAL SCIENCES (GLOBAL MEETING OF SOCIAL SCIENCE COMMUNITY), 2018, : 13 - 26
  • [50] The virtual rolling mill - Effective steps towards cyber physical system
    Das virtuelle walzwerk - Wirksame schritte zum cyber physical system
    1600, DIV Deutscher Industrieverlag GmbH (74):