Towards Comprehensive Protection for OpenFlow Controllers

被引:0
|
作者
Zhang, Shengzhi [1 ]
Jia, Xiaoqi [2 ,3 ]
Zhang, Weijuan [2 ,3 ]
机构
[1] Florida Inst Technol, Sch Comp, Melbourne, FL 32901 USA
[2] Chinese Acad Sci, Inst Informat Engn, State Key Lab Informat Secur, Beijing, Peoples R China
[3] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
OpenFlow has recently emerged as a powerful paradigm to help build dynamic, adaptive and agile networks. By decoupling control plane from data plane, OpenFlow allows network operators to program a centralized intelligence, OpenFlow controller, to manage network-wide traffic flows to meet the changing needs. However, from the security's point of view, a buggy or even malicious controller could compromise the control logic, and then the entire network. Even worse, the recent attack Stuxnet on industrial control systems also indicates the similar, severe threat to OpenFlow controllers from the commercial operating systems they are running on. In this paper, we comprehensively studied the attack vectors against the OpenFlow critical component, controller, and proposed a cross layer diversity approach that enables OpenFlow controllers to detect attacks, corruptions, failures, and then automatically continue correct execution. Case studies demonstrate that our approach can protect OpenFlow controllers from threats coming from compromised operating systems and themselves.
引用
收藏
页码:82 / 87
页数:6
相关论文
共 50 条
  • [21] Energy consumer in the Cuban legal system: Towards comprehensive protection
    Cordova, Jose Grabiel Luis
    Rivero, Darlin Leidys Rodriguez
    JOURNAL OF WORLD ENERGY LAW & BUSINESS, 2023, 16 (04): : 309 - 319
  • [22] Towards a resilient OpenFlow channel through MPTCP
    Gonzalez, Sergio
    de la Oliva, Antonio
    Bernardos, Carlos J.
    Contreras, Luis M.
    2018 13TH IEEE INTERNATIONAL SYMPOSIUM ON BROADBAND MULTIMEDIA SYSTEMS AND BROADCASTING (BMSB), 2018,
  • [23] Towards an Adaptive and Effective IDS Using OpenFlow
    Seeber, Sebastian
    Rodosek, Gabi Dreo
    INTELLIGENT MECHANISMS FOR NETWORK CONFIGURATION AND SECURITY, 2015, 9122 : 134 - 139
  • [24] Towards OpenFlow Based Software Defined Networks
    Chhikara, Pallavi
    Matharu, Gurpreet Singh
    Deep, Vikas
    2014 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMPUTING RESEARCH (IEEE ICCIC), 2014, : 477 - 482
  • [25] OpenFlow-Based Segment Protection in Ethernet Networks
    Sgambelluri, Andrea
    Giorgetti, Alessio
    Cugini, Filippo
    Paolucci, Francesco
    Castoldi, Piero
    JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2013, 5 (09) : 1066 - 1075
  • [26] A Novel Protection Design for OpenFlow-Based Networks
    Kitsuwan, Nattapong
    Payne, David B.
    Ruffini, Marco
    2014 16TH INTERNATIONAL CONFERENCE ON TRANSPARENT OPTICAL NETWORKS (ICTON), 2014,
  • [27] Efficient switch clustering for distributed controllers of OpenFlow network with bi-connectivity
    Nagano, Junichi
    Shinomiya, Norihiko
    COMPUTER NETWORKS, 2016, 96 : 48 - 57
  • [28] Performance Analysis of an OpenFlow-Enabled Network with POX, Ryu, and ODL Controllers
    Das, Dipan
    Sahoo, Bibhudatta
    Roy, Sharmistha
    Mohanty, Sagarika
    IETE JOURNAL OF RESEARCH, 2024, : 8538 - 8555
  • [29] Towards Neutrality in Access Networks: A NANDO Deployment with OpenFlow
    Matias, Jon
    Jacob, Eduardo
    Toledo, Nerea
    Astorga, Jasone
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON ACCESS NETWORKS (ACCESS 2011), 2011, : 7 - 12
  • [30] E-Balance: An Energy Aware Load Balancer based on Distributed OpenFlow Controllers
    Habibi, Pooyan
    Mokhtari, Masoud
    Sabaei, Masoud
    2016 24TH IRANIAN CONFERENCE ON ELECTRICAL ENGINEERING (ICEE), 2016, : 1740 - 1745