B-DAC: A decentralized access control framework on Northbound interface for securing SDN using blockchain

被引:5
|
作者
Phan The Duy
Hien Do Hoang
Do Thi Thu Hien
Anh Gia-Tuan Nguyen
Van-Hau Pham [1 ]
机构
[1] Vietnam Natl Univ, Ho Chi Minh City, Vietnam
关键词
SDN security; Access control policy; Northbound interface; Blockchain adoption; SOFTWARE-DEFINED NETWORKING; PRIVATE-BLOCKCHAIN; MANAGEMENT; IOT;
D O I
10.1016/j.jisa.2021.103080
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Network (SDN) is a new arising terminology of network architecture with outstanding features of orchestration by decoupling the control plane and the data plane in each network element. Even though it brings several benefits, SDN is vulnerable to a diversity of attacks. Abusing the single point of failure in the SDN controller component, hackers can shut down all network operations. More specifics, a malicious OpenFlow application can access to SDN controller to carry out harmful actions without any limitation owing to the lack of the access control mechanism as a standard in the Northbound. The sensitive information about the whole network such as network topology, flow information, and statistics can be gathered and leaked out. Even worse, the entire network can be taken over by the compromised controller. Hence, it is vital to build a scheme of access control for SDN's Northbound. Furthermore, it must also protect the data integrity and availability during data exchange between application and controller. To address such limitations, we introduce B-DAC, a blockchain-based framework for decentralized authentication and fine-grained access control for the Northbound interface to assist administrators in managing and protecting critical resources. With strict policy enforcement, B-DAC can perform decentralized access control for each request to keep network applications under surveillance for preventing over-privileged activities or security policy conflicts. To demonstrate the feasibility of our approach, we also implement a prototype of this framework to evaluate the security impact, effectiveness, and performance through typical use cases.
引用
收藏
页数:19
相关论文
共 19 条
  • [1] Controller DAC: Securing SDN Controller with Dynamic Access Control
    Tseng, Yuchia
    Pattaranantakul, Montida
    He, Ruan
    Zhang, Zonghua
    Nait-Ahdesselam, Farid
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [2] A Security-Enhanced Monitoring System for Northbound Interface in SDN using Blockchain
    Hien Do Hoang
    Phan The Duy
    Van-Hau Pham
    [J]. SOICT 2019: PROCEEDINGS OF THE TENTH INTERNATIONAL SYMPOSIUM ON INFORMATION AND COMMUNICATION TECHNOLOGY, 2019, : 197 - 204
  • [3] DACAS: integration of attribute-based access control for northbound interface security in SDN
    Yifan Liu
    Bo Zhao
    Yang An
    Jiabao Guo
    [J]. World Wide Web, 2023, 26 : 2143 - 2173
  • [4] BENBI: Scalable and Dynamic Access Control on the Northbound Interface of SDN-Based VANET
    Weng, Jia-Si
    Weng, Jian
    Zhang, Yue
    Luo, Weiqi
    Lan, Weiming
    [J]. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2019, 68 (01) : 822 - 831
  • [5] DACAS: integration of attribute-based access control for northbound interface security in SDN
    Liu, Yifan
    Zhao, Bo
    An, Yang
    Guo, Jiabao
    [J]. WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2023, 26 (04): : 2143 - 2173
  • [6] A Decentralized Smart Grid Communication Framework Using SDN-enabled Blockchain
    Ghosh, Uttam
    Njilla, Laurent
    Shetty, Sachin
    Kamhoua, Charles A.
    [J]. 2024 IEEE 21ST CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2024, : 982 - 985
  • [7] Decentralized, BlockChain Based Access Control Framework for the Heterogeneous Internet of Things
    Dukkipati, Chethana
    Zhang, Yunpeng
    Cheng, Liang Chieh
    [J]. PROCEEDINGS OF THE THIRD ACM WORKSHOP ON ATTRIBUTE-BASED ACCESS CONTROL (ABAC'18), 2018, : 61 - 69
  • [8] Decentralized Access Control Infrastructure Using Blockchain for Big Data
    Mounnan, Oussama
    Abou El Kalam, Anas
    El Haourani, Lamia
    [J]. 2019 IEEE/ACS 16TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA 2019), 2019,
  • [9] Decentralized Access Control using Blockchain Technology for Application in Smart Farming
    Noor, Normaizeerah Mohd
    Razali, Noor Afiza Mat
    Malizan, Nur Atiqah
    Wook, Muslihah
    Hasbullah, Nor Asiakin
    Ishak, Khairul Khalil
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (09) : 788 - 802
  • [10] Blockchain-Based Framework for Privacy Preservation and Securing EHR with Patient-Centric Access Control
    Puneeth, Reval Prabhu
    Parthasarathy, Govindaswamy
    [J]. ACTA INFORMATICA PRAGENSIA, 2024, 13 (01)