Securing the Software-Defined Network Control Layer

被引:56
|
作者
Porras, Phillip [1 ]
Cheung, Steven [1 ]
Fong, Martin [1 ]
Skinner, Keith [1 ]
Yegneswaran, Vinod [1 ]
机构
[1] SRI Int, Comp Sci Lab, Menlo Pk, CA 94025 USA
关键词
VERIFICATION;
D O I
10.14722/ndss.2015.23222
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networks (SDNs) pose both an opportunity and challenge to the network security community. The opportunity lies in the ability of SDN applications to express intelligent and agile threat mitigation logic against hostile flows, without the need for specialized inline hardware. However, the SDN community lacks a secure control-layer to manage the interactions between the application layer and the switch infrastructure (the data plane). There are no available SDN controllers that provide the key security features, trust models, and policy mediation logic, necessary to deploy multiple SDN applications into a highly sensitive computing environment. We propose the design of security extensions at the control layer to provide the security management and arbitration of conflicting flow rules that arise when multiple applications are deployed within the same network. We present a prototype of our design as a Security Enhanced version of the widely used OpenFlow Floodlight Controller, which we call SE-Floodlight. SE-Floodlight extends Floodlight with a security-enforcement kernel (SEK) layer, whose functions are also directly applicable to other OpenFlow controllers. The SEK adds a unique set of secure application management features, including an authentication service, role-based authorization, a permission model for mediating all configuration change requests to the data-plane, inline flow-rule conflict resolution, and a security audit service. We demonstrate the robustness and scalability of our system implementation through both a comprehensive functionality assessment and a performance evaluation that illustrates its sub-linear scaling properties.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Securing Network Using Software-Defined Networking in Control and Data Planes
    Pawar, Nishant S.
    Arunvel, A.
    Kumar, Gardas Naresh
    Sinha, Aditya Kumar
    [J]. COMPUTING AND NETWORK SUSTAINABILITY, 2019, 75
  • [2] Securing the Control Channel of Software-Defined Mobile Networks
    Liyanage, Madhusanka
    Ylianttila, Mika
    Gurtov, Andrei
    [J]. 2014 IEEE 15TH INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM), 2014,
  • [3] On Securing Healthcare with Software-Defined Networks
    Gupta, Sahil
    Acharya, H. B.
    Kwon, Minseok
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM 2019 WKSHPS), 2019, : 354 - 359
  • [4] Securing Software-Defined Vehicular Network Architecture against DDoS attack
    Amari, Houda
    Louati, Wassef
    Khoukhi, Lyes
    Belguith, Lamia Hadrich
    [J]. PROCEEDINGS OF THE IEEE 46TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2021), 2021, : 653 - 656
  • [5] FlowIdentity: Software-Defined Network Access Control
    Yakasai, Sadiq T.
    Guy, Chris G.
    [J]. 2015 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORK (NFV-SDN), 2015, : 115 - 120
  • [6] Securing industrial communication with software-defined networking
    Savaliya, Abhishek
    Jhaveri, Rutvij H.
    Xin, Qin
    Alqithami, Saad
    Ramani, Sagar
    Ahanger, Tariq Ahamed
    [J]. MATHEMATICAL BIOSCIENCES AND ENGINEERING, 2021, 18 (06) : 8298 - 8313
  • [7] Securing Data Planes in Software-Defined Networks
    Chao, Tzu-Wei
    Ke, Yu-Ming
    Chen, Bo-Han
    Chen, Jhu-Lin
    Hsieh, Chen Jung
    Lee, Shao-Chuan
    Hsiao, Hsu-Chun
    [J]. 2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 465 - 470
  • [8] Cross Layer Optimization of Wireless Control Links in the Software-Defined LEO Satellite Network
    Cho, Woncheol
    Choi, Jihwan P.
    [J]. IEEE ACCESS, 2019, 7 : 113534 - 113547
  • [9] Software-defined converged access network with cross-layer intelligent control architecture
    Liu, Tao
    Qin, Panke
    Li, Lixiang
    Tang, Yongli
    [J]. OPTICAL FIBER TECHNOLOGY, 2019, 50 : 242 - 249
  • [10] Gavel: Software-Defined Network Control with Graph Databases
    Barakat, Osamah L.
    Koll, David
    Fu, Xiaoming
    [J]. PROCEEDINGS OF THE 2017 20TH CONFERENCE ON INNOVATIONS IN CLOUDS, INTERNET AND NETWORKS (ICIN), 2017, : 279 - 286