Towards Comprehensive Protection for OpenFlow Controllers

被引:0
|
作者
Zhang, Shengzhi [1 ]
Jia, Xiaoqi [2 ,3 ]
Zhang, Weijuan [2 ,3 ]
机构
[1] Florida Inst Technol, Sch Comp, Melbourne, FL 32901 USA
[2] Chinese Acad Sci, Inst Informat Engn, State Key Lab Informat Secur, Beijing, Peoples R China
[3] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
OpenFlow has recently emerged as a powerful paradigm to help build dynamic, adaptive and agile networks. By decoupling control plane from data plane, OpenFlow allows network operators to program a centralized intelligence, OpenFlow controller, to manage network-wide traffic flows to meet the changing needs. However, from the security's point of view, a buggy or even malicious controller could compromise the control logic, and then the entire network. Even worse, the recent attack Stuxnet on industrial control systems also indicates the similar, severe threat to OpenFlow controllers from the commercial operating systems they are running on. In this paper, we comprehensively studied the attack vectors against the OpenFlow critical component, controller, and proposed a cross layer diversity approach that enables OpenFlow controllers to detect attacks, corruptions, failures, and then automatically continue correct execution. Case studies demonstrate that our approach can protect OpenFlow controllers from threats coming from compromised operating systems and themselves.
引用
收藏
页码:82 / 87
页数:6
相关论文
共 50 条
  • [1] Feedback ARMA Models versus Bayesian Models towards Securing OpenFlow Controllers for SDNs
    Aly, Wael Hosny Fouad
    Kanj, Hassan
    Mostafa, Nour
    Alabed, Samer
    ELECTRONICS, 2022, 11 (09)
  • [2] EventBus Module for Distributed OpenFlow Controllers
    Alekseev, Igor
    Nikitinskiy, Mikhail
    PROCEEDINGS OF THE 17TH CONFERENCE OF OPEN INNOVATIONS ASSOCIATION FRUCT, 2015, : 3 - 8
  • [3] Experimental Evaluation of Two OpenFlow Controllers
    Darianian, Mohamad
    Williamson, Carey
    Haque, Israat
    2017 IEEE 25TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2017,
  • [4] OFMon: OpenFlow Monitoring System in ONOS Controllers
    Kim, Woojoong
    Li, Jian
    Hong, James Won-Ki
    Suh, Young-Joo
    2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 397 - 402
  • [5] Performance evaluation of OpenFlow controllers for network virtualization
    Turull, Daniel
    Hidell, Markus
    Sjodin, Peter
    2014 IEEE 15TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (HPSR), 2014, : 50 - 56
  • [6] RAPTOR: A REST API TranslaTOR for OpenFlow Controllers
    Rivera, Sergio
    Fei, Zongming
    Griffioen, James
    2016 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2016,
  • [7] Towards a Detailed OpenFlow Emulator
    Cheng, Yi-Jun
    Huang, Daniel
    Lee, Cheng-Lin
    Lee, Mu-Che
    Chuang, Bo-Wei
    Tsai, Meng-Chen
    Huang, Xin
    Hsu, Cheng-Hsin
    2015 17TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM APNOMS, 2015, : 127 - 132
  • [8] Towards comprehensive privacy protection in data clustering
    Zhang, Nan
    Advances in Knowledge Discovery and Data Mining, Proceedings, 2007, 4426 : 1096 - 1104
  • [9] OrchFlow: An Architecture for Orchestration of Multiple Controllers in OpenFlow Networks
    Marcelo Frate
    Marcelo K. Marczuk
    Fábio L. Verdi
    Journal of Network and Systems Management, 2019, 27 : 551 - 572
  • [10] OrchFlow: An Architecture for Orchestration of Multiple Controllers in OpenFlow Networks
    Frate, Marcelo
    Marczuk, Marcelo K.
    Verdi, Fabio L.
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2019, 27 (03) : 551 - 572