A Security-Enhanced Monitoring System for Northbound Interface in SDN using Blockchain

被引:8
|
作者
Hien Do Hoang [1 ]
Phan The Duy [1 ]
Van-Hau Pham [1 ]
机构
[1] VNU HCM, Univ Informat Technol, Informat Secur Lab, Ho Chi Minh City, Vietnam
关键词
Software Defined Networking; Blockchain; Northbound Interface; AAA;
D O I
10.11453368926.3369709
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In Software-Defined Networking (SDN), Northbound Interface provides APIs, which allow network applications to communicate with SDN controllers. However, a malicious application can access to SDN controller and perform illegal activities via these APIs. Although some studies proposed AAA (Authentication, Authorization, Accounting) systems to protect SDN controllers from malicious applications, their proposed systems also exist several limitations. Attackers can compromise a system, then modify its database or files to gain higher privileges. This system can be taken down because of Single Point of Failure threat. To enhance security for the Northbound interface, we propose a novel system using blockchain, namely BlockAS. It is used to authenticate, authorize and monitor accessing critical controller resources from applications. Specifically, BlockAS leverages blockchain features to maintain the immutability and decentralization of credential data. Our proposed system has five key properties: immutability of database, decentralization, authentication, authorization, and accounting to enhance security for SDN controller and its offered services.
引用
收藏
页码:197 / 204
页数:8
相关论文
共 50 条
  • [1] B-DAC: A decentralized access control framework on Northbound interface for securing SDN using blockchain
    Phan The Duy
    Hien Do Hoang
    Do Thi Thu Hien
    Anh Gia-Tuan Nguyen
    Van-Hau Pham
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 64
  • [2] DACAS: integration of attribute-based access control for northbound interface security in SDN
    Yifan Liu
    Bo Zhao
    Yang An
    Jiabao Guo
    [J]. World Wide Web, 2023, 26 : 2143 - 2173
  • [3] Social Data Driven SDN Network Operation using Northbound Interface
    Tairaku, Tsumugi
    Nakao, Akihiro
    Yamamoto, Shu
    Yamaguchi, Saneyasu
    Oguchi, Masato
    [J]. 2018 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2018, : 702 - 706
  • [4] DACAS: integration of attribute-based access control for northbound interface security in SDN
    Liu, Yifan
    Zhao, Bo
    An, Yang
    Guo, Jiabao
    [J]. WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2023, 26 (04): : 2143 - 2173
  • [5] Security-Enhanced SDN Controller Based. Kerberos Authentication Protocol
    Mutaher, Hamza
    Kumar, Pradeep
    [J]. 2021 11TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, DATA SCIENCE & ENGINEERING (CONFLUENCE 2021), 2021, : 672 - 677
  • [6] Implementing Security-Enhanced PHR System in the Cloud using FAME
    Ying, Zuobin
    Jiang, Wenjie
    Liu, Ximeng
    Xu, Shengmin
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [7] Security-Enhanced OFDM-PON Using Hybrid Chaotic System
    Cheng, Mengfan
    Deng, Lei
    Gao, Xiaojing
    Li, Hao
    Tang, Ming
    Fu, Songnian
    Shum, Ping
    Liu, Deming
    [J]. IEEE PHOTONICS TECHNOLOGY LETTERS, 2015, 27 (03) : 326 - 329
  • [8] SECURITY-ENHANCED SEARCH AND RESCUE SYSTEM BY USING LTE AND COSPAS SARSAT
    Lee, Sanguk
    Jeong, I. C.
    Kim, Jaehyun
    Ahn, Woo-Geun
    [J]. 11TH ANNUAL BASKA GNSS CONFERENCE, 2017, : 109 - 119
  • [9] BCNBI: A Blockchain-Based Security Framework for Northbound Interface in Software-Defined Networking
    Algarni, Sultan
    Eassa, Fathy
    Almarhabi, Khalid
    Algarni, Abdullah
    Albeshri, Aiiad
    [J]. ELECTRONICS, 2022, 11 (07)
  • [10] A Security-enhanced Advertising Platform based on Blockchain and Edge Computing in Generative AI
    Jing, Zhengjun
    Xu, Xiaolong
    Gu, Chunseng
    Zhang, Yan
    Shu, Qiang
    [J]. APPLIED ARTIFICIAL INTELLIGENCE, 2024, 38 (01)