SDNsec: Forwarding Accountability for the SDN Data Plane

被引:0
|
作者
Sasaki, Takayuki [1 ]
Pappas, Christos [2 ]
Lee, Taeho [2 ]
Hoefler, Torsten [2 ]
Perrig, Adrian [2 ]
机构
[1] NEC Corp Ltd, Tokyo, Japan
[2] Swiss Fed Inst Technol, Zurich, Switzerland
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN promises to make networks more flexible, programmable, and easier to manage. Inherent security problems in SDN today, however, pose a threat to the promised benefits. First, the network operator lacks tools to proactively ensure that policies will be followed or to reactively inspect the behavior of the network. Second, the distributed nature of state updates at the data plane leads to inconsistent network behavior during reconfigurations. Third, the large flow space makes the data plane susceptible to state exhaustion attacks. This paper presents SDNsec, an SDN security extension that provides forwarding accountability for the SDN data plane. Forwarding rules are encoded in the packet, ensuring consistent network behavior during reconfigurations and limiting state exhaustion attacks due to table lookups. Symmetric-key cryptography is used to protect the integrity of the forwarding rules and enforce them at each switch. A complementary path validation mechanism allows the controller to reactively examine the actual path taken by the packets. Furthermore, we present mechanisms for secure link-failure recovery.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Multi-path Load Balancing for SDN Data Plane
    Nkosi, M. C.
    Lysko, A. A.
    Dlamini, S.
    2018 INTERNATIONAL CONFERENCE ON INTELLIGENT AND INNOVATIVE COMPUTING APPLICATIONS (ICONIC), 2018, : 229 - 234
  • [42] AI-Driven Packet Forwarding With Programmable Data Plane: A Survey
    Quan, Wei
    Xu, Ziheng
    Liu, Mingyuan
    Cheng, Nan
    Liu, Gang
    Gao, Deyun
    Zhang, Hongke
    Shen, Xuemin
    Zhuang, Weihua
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2023, 25 (01): : 762 - 790
  • [43] A tool for tracing network data plane via SDN/OpenFlow
    Wang, Yangyang
    Bi, Jun
    Zhang, Keyao
    SCIENCE CHINA-INFORMATION SCIENCES, 2017, 60 (02)
  • [44] Flowinsight: decoupling visibility from operability in SDN data plane
    Li, Yuliang
    Yao, Guang
    Bi, Jun
    SIGCOMM'14: PROCEEDINGS OF THE 2014 ACM CONFERENCE ON SPECIAL INTEREST GROUP ON DATA COMMUNICATION, 2014, : 137 - 138
  • [45] FlowInsight: Decoupling Visibility from Operability in SDN Data Plane
    Li, Yuliang
    Yao, Guang
    Bi, Jun
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (04) : 137 - 138
  • [46] StateFit: A security framework for SDN programmable data plane model
    Hwang, Ren-Hung
    Van-Linh Nguyen
    Lin, Po-Ching
    2018 15TH INTERNATIONAL SYMPOSIUM ON PERVASIVE SYSTEMS, ALGORITHMS AND NETWORKS (I-SPAN 2018), 2018, : 160 - 165
  • [47] Stochastic Pre-Classification for SDN Data Plane Matching
    McHale, Luke
    Casey, Jasson
    Gratz, Paul V.
    Sprintson, Alex
    2014 IEEE 22ND INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2014, : 596 - 602
  • [48] FORTRESS: An Efficient and Distributed Firewall for Stateful Data Plane SDN
    Caprolu, Maurantonio
    Raponi, Simone
    Di Pietro, Roberto
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
  • [49] DDoS Attack Detection and Mitigation at SDN Data Plane Layer
    Abdulkarem, Huda Saleh
    Dawod, Ammar
    2020 IEEE 2ND GLOBAL POWER, ENERGY AND COMMUNICATION CONFERENCE (IEEE GPECOM2020), 2020, : 322 - 326
  • [50] Fast failure detection and recovery in SDN with stateful data plane
    Cascone, Carmelo
    Sanvito, Davide
    Pollini, Luca
    Capone, Antonio
    Sanso, Brunilde
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2017, 27 (02)