An improved network security situation assessment approach in software defined networks

被引:38
|
作者
Fan, Zhijie [1 ,4 ,5 ]
Xiao, Ya [2 ]
Nayak, Amiya [4 ]
Tan, Chengxiang [3 ]
机构
[1] Tongji Univ, Shanghai, Peoples R China
[2] Tongji Univ, Comp Sci & Engn, Shanghai, Peoples R China
[3] Tongji Univ, Comp Sci, Shanghai, Peoples R China
[4] Univ Ottawa, Sch Elect Engn & Comp Sci, Ottawa, ON, Canada
[5] Minist Publ Secur, Res Inst 3, Shanghai, Peoples R China
基金
国家重点研发计划;
关键词
Software defined network; Security situation awareness; Attack detection; Hidden Markov model; ALGORITHM;
D O I
10.1007/s12083-017-0604-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Network (SDN) is a network framework which can be controlled and defined by software programming, and OpenFlow is the basic protocol in SDN that defines the communication protocol between SDN control plane and data plane. With the deployment of SDN in reality, many security threats and issues are of great concern. In this paper, we propose a security situation awareness approach for SDN. This approach focuses on the attacks like network scanning attack, OpenFlow flooding attack, switch compromised attack and ARP attack in both data plane and control plane. Based on the features of these attacks, we use multiple observations hidden Markov model (HMM) to quantify the network status and then get the security situation assessment values for SDN. The proposed approach can also detect these four attacks and predict the network status based on HMM when given a sequence of observed feature values. We build a test scenario to simulate our approach with Ryu controller and OpenFlow switch and prove the feasibility of this approach.
引用
收藏
页码:295 / 309
页数:15
相关论文
共 50 条
  • [1] An improved network security situation assessment approach in software defined networks
    Zhijie Fan
    Ya Xiao
    Amiya Nayak
    Chengxiang Tan
    [J]. Peer-to-Peer Networking and Applications, 2019, 12 : 295 - 309
  • [2] Introducing Network Situation Awareness into Software Defined Wireless Networks
    Zhao, Xing
    Lei, Tao
    Lu, Zhaoming
    Wen, Xiangming
    Jiang, Shan
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2018, 12 (03): : 1063 - 1082
  • [3] DELTA: A Security Assessment Framework for Software-Defined Networks
    Lee, Seungsoo
    Yoon, Changhoon
    Lee, Chanhee
    Shin, Seungwon
    Yegneswaran, Vinod
    Porras, Phillip
    [J]. 24TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2017), 2017,
  • [4] A comprehensive security assessment framework for software-defined networks
    Lee, Seungsoo
    Kim, Jinwoo
    Woo, Seungwon
    Yoon, Changhoon
    Scott-Hayward, Sandra
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    [J]. COMPUTERS & SECURITY, 2020, 91
  • [5] Improved Handshaking Procedures for Transport Layer Security in Software Defined Networks
    Li, Xue Jun
    Ma, Maode
    Hlaing, Cho Wai
    [J]. 2021 IEEE REGION 10 CONFERENCE (TENCON 2021), 2021, : 305 - 310
  • [6] An Experimental Software Defined Security Controller for Software Defined Network
    Al-Zewairi, Malek
    Suleiman, Dima
    Almajali, Sufyan
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 32 - 36
  • [7] Opportunities and Challenges of Software-Defined Mobile Networks in Network Security
    Liyanage, Madhusanka
    Abro, Ahmed Bux
    Ylianttila, Mika
    Gurtov, Andrei
    [J]. IEEE SECURITY & PRIVACY, 2016, 14 (04) : 34 - 44
  • [8] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    [J]. 2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [9] A Survey of Security in Software Defined Networks
    Scott-Hayward, Sandra
    Natarajan, Sriram
    Sezer, Sakir
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2016, 18 (01): : 623 - 654
  • [10] Security of Software Defined Networks: A survey
    Alsmadr, Izzat
    Xu, Dianxiang
    [J]. COMPUTERS & SECURITY, 2015, 53 : 79 - 108