SENAD: Securing Network Application Deployment in Software Defined Networks

被引:0
|
作者
Tseng, Yuchia [1 ]
Nait-Abdesselam, Farid [2 ]
Khokhar, Ashfaq [3 ]
机构
[1] Paris Descartes Univ, IRT Syst X, Paris, France
[2] Paris Descartes Univ, Paris, France
[3] Iowa State Univ, Ames, IA USA
关键词
SDN controller; network applications; security-by-design;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The Software Defined Networks (SDN) paradigm, often referred to as a radical new idea in networking, promises to dramatically simplify network management by enabling innovation through network programmability. However, notable security issues, such as app-to-control threats, remain a significant concern that impedes SDN from being widely adopted. To cope with those app-to-control threats, this paper proposes a solution to securely deploy valid network applications while protecting the SDN controller against the injection of the malicious application. This problem is mitigated by proposing a novel SDN architecture, dubbed SENAD, which splits the well-known SDN controller into: (1) a data plane controller (DPC), and (2) an application plane controller (APC), to secure this latter by design. The role of the DPC is dedicated for interpreting the network rules into OpenFlow entries and maintaining the communication with the data plane. The role of the APC, however, is to provide a secured runtime for deploying the network applications, including authentication, access control, resource isolation, control, and monitoring applications. We show that this approach can easily shield against any deny of service, caused for instance by the resource exhaustion attack or the malicious command injection, that is caused by the co-existence of a malicious application on the controller's runtime. The evaluation of our architecture shows that the packet_in messages take less than 5 ms to be delivered from the data plane to the application plane on the long range.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Joint Optimization of VNF Deployment and Routing in Software Defined Satellite Networks
    Jia, Ziye
    Sheng, Min
    Li, Jiandong
    Liu, Runzi
    Guo, Kun
    Wang, Yu
    Chen, Dong
    Ding, Rui
    [J]. 2018 IEEE 88TH VEHICULAR TECHNOLOGY CONFERENCE (VTC-FALL), 2018,
  • [32] Securing Wireless Software Defined Networks: Appraising Threats, Defenses & Research Challenges
    Bakhshi, Taimur
    [J]. 2018 INTERNATIONAL CONFERENCE ON ADVANCEMENTS IN COMPUTATIONAL SCIENCES (ICACS), 2018, : 31 - 36
  • [33] Application Performance Monitoring in Software Defined Networks
    Dasari, Subramanyeswara Rao
    Sasirekha, G. V. K.
    [J]. 2016 26TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2016, : 89 - 94
  • [34] A Service Function Chain Deployment Scheme of the Software Defined Satellite Network
    Qiao, Wenxin
    Ni, Xianglong
    Lu, Yu
    Li, Xiongwei
    Zhao, Donghao
    Liu, Yicen
    [J]. MOBILE INFORMATION SYSTEMS, 2022, 2022
  • [35] Securing Internet of Things System using Software Defined Network based Architecture
    Ariffin, Sharifah H. S.
    [J]. 2020 IEEE INTERNATIONAL RF AND MICROWAVE CONFERENCE (RFM), 2020,
  • [36] Securing Network Using Software-Defined Networking in Control and Data Planes
    Pawar, Nishant S.
    Arunvel, A.
    Kumar, Gardas Naresh
    Sinha, Aditya Kumar
    [J]. COMPUTING AND NETWORK SUSTAINABILITY, 2019, 75
  • [37] Securing Software-Defined Vehicular Network Architecture against DDoS attack
    Amari, Houda
    Louati, Wassef
    Khoukhi, Lyes
    Belguith, Lamia Hadrich
    [J]. PROCEEDINGS OF THE IEEE 46TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2021), 2021, : 653 - 656
  • [38] Assignment of Virtual Networks to Substrate Network for Software Defined Networks
    Nasiri, Ali Akbar
    Derakhshan, Farnaz
    [J]. INTERNATIONAL JOURNAL OF CLOUD APPLICATIONS AND COMPUTING, 2018, 8 (04) : 29 - 48
  • [39] From Software Defined Network To Network Defined for Software
    Trois, Celio
    Martinello, Magnos
    de Bona, Luis C. E.
    Del Fabro, Marcos D.
    [J]. 30TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, VOLS I AND II, 2015, : 665 - 668
  • [40] Flexible network management and application service adaptability in software defined wireless sensor networks
    Modieginyane, Kgotlaetsile Mathews
    Malekian, Reza
    Letswamotse, Babedi Betty
    [J]. JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2019, 10 (04) : 1621 - 1630