SDNsec: Forwarding Accountability for the SDN Data Plane

被引:0
|
作者
Sasaki, Takayuki [1 ]
Pappas, Christos [2 ]
Lee, Taeho [2 ]
Hoefler, Torsten [2 ]
Perrig, Adrian [2 ]
机构
[1] NEC Corp Ltd, Tokyo, Japan
[2] Swiss Fed Inst Technol, Zurich, Switzerland
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN promises to make networks more flexible, programmable, and easier to manage. Inherent security problems in SDN today, however, pose a threat to the promised benefits. First, the network operator lacks tools to proactively ensure that policies will be followed or to reactively inspect the behavior of the network. Second, the distributed nature of state updates at the data plane leads to inconsistent network behavior during reconfigurations. Third, the large flow space makes the data plane susceptible to state exhaustion attacks. This paper presents SDNsec, an SDN security extension that provides forwarding accountability for the SDN data plane. Forwarding rules are encoded in the packet, ensuring consistent network behavior during reconfigurations and limiting state exhaustion attacks due to table lookups. Symmetric-key cryptography is used to protect the integrity of the forwarding rules and enforce them at each switch. A complementary path validation mechanism allows the controller to reactively examine the actual path taken by the packets. Furthermore, we present mechanisms for secure link-failure recovery.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Integrating Legacy Forwarding Environment to OpenFlow/SDN Control Plane
    Farias, Fernando
    Salvatti, Joao
    Victor, Pedro
    Abelem, Antonio
    2013 15TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2013,
  • [2] Data Plane Programmability in SDN
    Farhady, Hamid
    Lee, HyunYong
    Nakao, Akihiro
    2014 IEEE 22ND INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2014, : 583 - 588
  • [3] Multipath Forwarding Strategies and SDN Control for Named Data Networking
    Alhowaidi, Mohammad
    Nadig, Deepak
    Ramamurthy, Byrav
    Bockelman, Brian
    Swanson, David
    2018 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (ANTS), 2018,
  • [4] Efficient Data Plane Protection for SDN
    Merling, Daniel
    Braun, Wolfgang
    Menth, Michael
    2018 4TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION AND WORKSHOPS (NETSOFT), 2018, : 10 - 18
  • [5] The Case for Data Plane Timestamping in SDN
    Mizrahi, Tal
    Moses, Yoram
    2016 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2016,
  • [6] ITor-SDN: Intelligent Tor Networks-Based SDN for Data Forwarding Management
    Yaseen, Fouad A.
    Alkhalidi, Nahlah Abdulrahman
    Al-Raweshidy, Hamed S.
    IEEE ACCESS, 2024, 12 : 4792 - 4800
  • [7] DATA ACCOUNTABILITY IN CLOUD USING RELIABLE LOG FILES FORWARDING
    Heames, R. N.
    Sudhakar, P.
    2013 INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND EMBEDDED SYSTEMS (ICICES), 2013, : 135 - 139
  • [8] RuleOut Forwarding Anomalies for SDN
    Xi, Shaoke
    Bu, Kai
    Mao, Wensen
    Zhang, Xiaoyu
    Ren, Kui
    Ren, Xinxin
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2023, 31 (01) : 395 - 407
  • [9] Enhancing security of SDN focusing on control plane and data plane
    Celesova, Barbora
    Val'ko, Jozef
    Grezo, Rudolf
    Helebrandt, Pavol
    2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,
  • [10] Fault Tolerant Data Plane Using SDN
    Yamansavascilar, Baris
    Baktir, Ahmet Cihat
    Ozgovde, Atay
    Ersoy, Cem
    2017 25TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2017,