A Study on Securing Software Defined Networks

被引:4
|
作者
Rasool, Raihan Ur [1 ]
Wang, Hua [1 ]
Rafique, Wajid [2 ]
Yong, Jianming [3 ]
Cao, Jinli [4 ]
机构
[1] Victoria Univ, Melbourne, Vic, Australia
[2] Natl Univ Sci & Technol, Islamabad, Pakistan
[3] Univ Southern Queensland, Toowoomba, Qld, Australia
[4] La Trobe Univ, Bundoora, Vic, Australia
关键词
Network security; Target link flooding; Software defined network; PURPOSE;
D O I
10.1007/978-3-319-68786-5_38
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Most of the IT infrastructure across the globe is virtualized and is backed by Software Defined Networks (SDN). Hence, any threat to SDN's core components would potentially mean to harm today's Internet and the very fabric of utility computing. After thorough analysis, this study identifies Crossfire link flooding technique as one of the lethal attacks that can potentially target the link connecting the control plane to the data plane in SDNs. In such a situation, the control plane may get disconnected, resulting in the degradation of the performance of the whole network and service disruption. In this work we present a detailed comparative analysis of the link flooding mitigation techniques and propose a framework for effective defense. It comprises of a separate controller consisting of a flood detection module, a link listener module and a flood detection module, which will work together to detect and mitigate attacks and facilitate the normal flow of traffic. This paper serves as a first effort towards identifying and mitigating the crossfire LFA on the channel that connects control plane to data plane in SDNs. We expect that further optimizations in the proposed solution can bring remarkable results.
引用
收藏
页码:479 / 489
页数:11
相关论文
共 50 条
  • [1] Securing Software Defined Wireless Networks
    He, Daojing
    Chan, Sammy
    Guizani, Mohsen
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2016, 54 (01) : 20 - 25
  • [2] Securing ARP in Software Defined Networks
    Alharbi, Talal
    Durando, Dario
    Pakzad, Farzaneh
    Portmann, Marius
    [J]. 2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 523 - 526
  • [3] Securing Distributed Control of Software Defined Networks
    Othman, Othman M. M.
    Okamura, Koji
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (09): : 5 - 14
  • [4] On Securing Healthcare with Software-Defined Networks
    Gupta, Sahil
    Acharya, H. B.
    Kwon, Minseok
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM 2019 WKSHPS), 2019, : 354 - 359
  • [5] A Survey of Securing Networks Using Software Defined Networking
    Ali, Syed Taha
    Sivaraman, Vijay
    Radford, Adam
    Jha, Sanjay
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2015, 64 (03) : 1086 - 1097
  • [6] Securing Data Planes in Software-Defined Networks
    Chao, Tzu-Wei
    Ke, Yu-Ming
    Chen, Bo-Han
    Chen, Jhu-Lin
    Hsieh, Chen Jung
    Lee, Shao-Chuan
    Hsiao, Hsu-Chun
    [J]. 2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 465 - 470
  • [7] Securing Smart Home Networks with Software-Defined Perimeter
    Sallam, Ahmed
    Refaey, Ahmed
    Shami, Abdallah
    [J]. 2019 15TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2019, : 1989 - 1993
  • [8] SENAD: Securing Network Application Deployment in Software Defined Networks
    Tseng, Yuchia
    Nait-Abdesselam, Farid
    Khokhar, Ashfaq
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2018,
  • [9] Securing Software Defined Networks: Taxonomy, Requirements, and Open Issues
    Akhunzada, Adnan
    Ahmed, Ejaz
    Gani, Abdullah
    Khan, Muhammad Khurram
    Imran, Muhammad
    Guizani, Sghaier
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (04) : 36 - 44
  • [10] The application of Software Defined Networking on securing computer networks: A survey
    Sahay, Rishikesh
    Meng, Weizhi
    Jensen, Christian D.
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 131 : 89 - 108