SENAD: Securing Network Application Deployment in Software Defined Networks

被引:0
|
作者
Tseng, Yuchia [1 ]
Nait-Abdesselam, Farid [2 ]
Khokhar, Ashfaq [3 ]
机构
[1] Paris Descartes Univ, IRT Syst X, Paris, France
[2] Paris Descartes Univ, Paris, France
[3] Iowa State Univ, Ames, IA USA
关键词
SDN controller; network applications; security-by-design;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The Software Defined Networks (SDN) paradigm, often referred to as a radical new idea in networking, promises to dramatically simplify network management by enabling innovation through network programmability. However, notable security issues, such as app-to-control threats, remain a significant concern that impedes SDN from being widely adopted. To cope with those app-to-control threats, this paper proposes a solution to securely deploy valid network applications while protecting the SDN controller against the injection of the malicious application. This problem is mitigated by proposing a novel SDN architecture, dubbed SENAD, which splits the well-known SDN controller into: (1) a data plane controller (DPC), and (2) an application plane controller (APC), to secure this latter by design. The role of the DPC is dedicated for interpreting the network rules into OpenFlow entries and maintaining the communication with the data plane. The role of the APC, however, is to provide a secured runtime for deploying the network applications, including authentication, access control, resource isolation, control, and monitoring applications. We show that this approach can easily shield against any deny of service, caused for instance by the resource exhaustion attack or the malicious command injection, that is caused by the co-existence of a malicious application on the controller's runtime. The evaluation of our architecture shows that the packet_in messages take less than 5 ms to be delivered from the data plane to the application plane on the long range.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] The application of Software Defined Networking on securing computer networks: A survey
    Sahay, Rishikesh
    Meng, Weizhi
    Jensen, Christian D.
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 131 : 89 - 108
  • [2] Securing Software Defined Wireless Networks
    He, Daojing
    Chan, Sammy
    Guizani, Mohsen
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2016, 54 (01) : 20 - 25
  • [3] A Study on Securing Software Defined Networks
    Rasool, Raihan Ur
    Wang, Hua
    Rafique, Wajid
    Yong, Jianming
    Cao, Jinli
    [J]. WEB INFORMATION SYSTEMS ENGINEERING, WISE 2017, PT II, 2017, 10570 : 479 - 489
  • [4] Securing ARP in Software Defined Networks
    Alharbi, Talal
    Durando, Dario
    Pakzad, Farzaneh
    Portmann, Marius
    [J]. 2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 523 - 526
  • [5] Securing Distributed Control of Software Defined Networks
    Othman, Othman M. M.
    Okamura, Koji
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (09): : 5 - 14
  • [6] On Securing Healthcare with Software-Defined Networks
    Gupta, Sahil
    Acharya, H. B.
    Kwon, Minseok
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM 2019 WKSHPS), 2019, : 354 - 359
  • [7] Programming the Network: Application Software Faults in Software-Defined Networks
    Jagadeesan, Lalita J.
    Mendiratta, Veena
    [J]. 2016 IEEE 27TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW), 2016, : 125 - 131
  • [8] A Survey of Securing Networks Using Software Defined Networking
    Ali, Syed Taha
    Sivaraman, Vijay
    Radford, Adam
    Jha, Sanjay
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2015, 64 (03) : 1086 - 1097
  • [9] Securing Data Planes in Software-Defined Networks
    Chao, Tzu-Wei
    Ke, Yu-Ming
    Chen, Bo-Han
    Chen, Jhu-Lin
    Hsieh, Chen Jung
    Lee, Shao-Chuan
    Hsiao, Hsu-Chun
    [J]. 2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 465 - 470
  • [10] Securing the Software-Defined Network Control Layer
    Porras, Phillip
    Cheung, Steven
    Fong, Martin
    Skinner, Keith
    Yegneswaran, Vinod
    [J]. 22ND ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2015), 2015,