SDNsec: Forwarding Accountability for the SDN Data Plane

被引:0
|
作者
Sasaki, Takayuki [1 ]
Pappas, Christos [2 ]
Lee, Taeho [2 ]
Hoefler, Torsten [2 ]
Perrig, Adrian [2 ]
机构
[1] NEC Corp Ltd, Tokyo, Japan
[2] Swiss Fed Inst Technol, Zurich, Switzerland
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN promises to make networks more flexible, programmable, and easier to manage. Inherent security problems in SDN today, however, pose a threat to the promised benefits. First, the network operator lacks tools to proactively ensure that policies will be followed or to reactively inspect the behavior of the network. Second, the distributed nature of state updates at the data plane leads to inconsistent network behavior during reconfigurations. Third, the large flow space makes the data plane susceptible to state exhaustion attacks. This paper presents SDNsec, an SDN security extension that provides forwarding accountability for the SDN data plane. Forwarding rules are encoded in the packet, ensuring consistent network behavior during reconfigurations and limiting state exhaustion attacks due to table lookups. Symmetric-key cryptography is used to protect the integrity of the forwarding rules and enforce them at each switch. A complementary path validation mechanism allows the controller to reactively examine the actual path taken by the packets. Furthermore, we present mechanisms for secure link-failure recovery.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] SDN-Based Dynamic Multipath Forwarding for Inter-Data Center Networking
    Wang, Yao-Chun
    Lin, Ying-Dar
    Chang, Guey-Yun
    2017 23RD IEEE INTERNATIONAL SYMPOSIUM ON LOCAL AND METROPOLITAN AREA NETWORKS (LANMAN), 2017,
  • [32] A Composite Pipeline for Forwarding Low-Latency Traffic in SDN Programmable Data Planes
    Ling, Zhiyuan
    Chen, Xiao
    Song, Lei
    ELECTRONICS, 2023, 12 (02)
  • [33] Towards a Novel Forwarding Strategy for Named Data Networking based on SDN and Bloom Filter
    Kalghoum, Anwar
    Gammar, Sonia Mettali
    Saidane, Leila Azouz
    2017 IEEE/ACS 14TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2017, : 1198 - 1204
  • [34] EPF-An Efficient Forwarding Mechanism in SDN Controller Enabled Named Data IoTs
    Tariq, Asadullah
    Rehman, Rana Asif
    Kim, Byung-Seo
    APPLIED SCIENCES-BASEL, 2020, 10 (21): : 1 - 22
  • [35] Application-Aware Flow Forwarding Service for SDN-Based Data Centers
    Lozano-Rizk, Jose E.
    Gonzalez-Trejo, Jose E.
    Rivera-Rodriguez, Raul
    Tchernykh, Andrei
    Villarreal-Reyes, Salvador
    Galaviz-Mosqueda, Alejandro
    ELECTRONICS, 2022, 11 (23)
  • [36] SDN-based dynamic multipath forwarding for inter-data center networking
    Wang, Yao-Chun
    Lin, Ying-Dar
    Chang, Guey-Yun
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2019, 32 (01)
  • [37] Extending SDN to Edge Fields for IoT-Centric Data Forwarding on Customized Routes
    Hu, Chin-Lin
    Hsu, Chao-Yu
    Khuukhenbaatar, Sod-Erdene
    Dashdorj, Yamkhin
    Tu, Jiun-Yu
    2019 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS - TAIWAN (ICCE-TW), 2019,
  • [38] Energy Efficient Priority Aware Forwarding in SDN Enabled Named Data Internet of Things
    Tariq, Asadullah
    Rehman, Rana Asif
    Kim, Byung-Seo
    2020 INTERNATIONAL CONFERENCE ON ELECTRONICS, INFORMATION, AND COMMUNICATION (ICEIC), 2020,
  • [39] LPV: Lightweight Packet Forwarding Verification in SDN
    Wang S.-Y.
    Li Q.
    Zhang Y.
    Jisuanji Xuebao/Chinese Journal of Computers, 2019, 42 (01): : 176 - 189
  • [40] Dynamic Offloading The SDN Control Plane In Large Area Networks By Condition-Aware Migration Of Forwarding Devices
    Tivig, Pantelimon-Teodor
    Borcoci, Eugen
    Vochin, Marius
    2022 25TH INTERNATIONAL SYMPOSIUM ON WIRELESS PERSONAL MULTIMEDIA COMMUNICATIONS (WPMC), 2022,