A Study on Securing Software Defined Networks

被引:4
|
作者
Rasool, Raihan Ur [1 ]
Wang, Hua [1 ]
Rafique, Wajid [2 ]
Yong, Jianming [3 ]
Cao, Jinli [4 ]
机构
[1] Victoria Univ, Melbourne, Vic, Australia
[2] Natl Univ Sci & Technol, Islamabad, Pakistan
[3] Univ Southern Queensland, Toowoomba, Qld, Australia
[4] La Trobe Univ, Bundoora, Vic, Australia
关键词
Network security; Target link flooding; Software defined network; PURPOSE;
D O I
10.1007/978-3-319-68786-5_38
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Most of the IT infrastructure across the globe is virtualized and is backed by Software Defined Networks (SDN). Hence, any threat to SDN's core components would potentially mean to harm today's Internet and the very fabric of utility computing. After thorough analysis, this study identifies Crossfire link flooding technique as one of the lethal attacks that can potentially target the link connecting the control plane to the data plane in SDNs. In such a situation, the control plane may get disconnected, resulting in the degradation of the performance of the whole network and service disruption. In this work we present a detailed comparative analysis of the link flooding mitigation techniques and propose a framework for effective defense. It comprises of a separate controller consisting of a flood detection module, a link listener module and a flood detection module, which will work together to detect and mitigate attacks and facilitate the normal flow of traffic. This paper serves as a first effort towards identifying and mitigating the crossfire LFA on the channel that connects control plane to data plane in SDNs. We expect that further optimizations in the proposed solution can bring remarkable results.
引用
收藏
页码:479 / 489
页数:11
相关论文
共 50 条
  • [21] Software Defined Networks
    Leon-Garcia, Alberto
    Ashwood-Smith, Peter
    Ganjali, Yashar
    [J]. COMPUTER NETWORKS, 2015, 92 : 209 - 210
  • [22] SOFTWARE DEFINED NETWORKS
    Li, Chung-Sheng
    Liao, Wanjiun
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (02) : 113 - 113
  • [23] SOFTWARE DEFINED NETWORKS
    Doughty, Mark
    [J]. JOURNAL OF THE INSTITUTE OF TELECOMMUNICATIONS PROFESSIONALS, 2015, 9 : 40 - 44
  • [24] Deep Reinforcement Learning for Securing Software-Defined Industrial Networks With Distributed Control Plane
    Wang, Jiadai
    Liu, Jiajia
    Guo, Hongzhi
    Mao, Bomin
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (06) : 4275 - 4285
  • [25] Securing industrial communication with software-defined networking
    Savaliya, Abhishek
    Jhaveri, Rutvij H.
    Xin, Qin
    Alqithami, Saad
    Ramani, Sagar
    Ahanger, Tariq Ahamed
    [J]. MATHEMATICAL BIOSCIENCES AND ENGINEERING, 2021, 18 (06) : 8298 - 8313
  • [26] Securing the Software-Defined Network Control Layer
    Porras, Phillip
    Cheung, Steven
    Fong, Martin
    Skinner, Keith
    Yegneswaran, Vinod
    [J]. 22ND ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2015), 2015,
  • [27] Securing Modern Network Architectures with Software Defined Networking
    Nowakowski, Piotr
    Zorawski, Piotr
    Cabaj, Krzysztof
    Mazurczyk, Wojciech
    [J]. 2019 6TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI 2019), 2019, : 235 - 238
  • [28] Study on Optimization for Software-Defined Networks Controller
    Alssaheli, Omran Maki Abdelsalam
    Abidin, Z. Zainal
    Zakaria, N. A.
    [J]. PROCEEDINGS OF INNOVATIVE RESEARCH AND INDUSTRIAL DIALOGUE 2018 (IRID'18), 2019, : 192 - 193
  • [29] Software-Defined IDS for Securing Embedded Mobile Devices
    Skowyra, Richard
    Bahargam, Sanaz
    Bestavros, Azer
    [J]. 2013 IEEE CONFERENCE ON HIGH PERFORMANCE EXTREME COMPUTING (HPEC), 2013,
  • [30] SOFTWARE DEFINED HEALTHCARE NETWORKS
    Hu, Long
    Qiu, Meikang
    Song, Jeungeun
    Hossain, M. Shamim
    Ghoneim, Ahmed
    [J]. IEEE WIRELESS COMMUNICATIONS, 2015, 22 (06) : 67 - 75