The (In)Security of Virtualization in Software Defined Networks

被引:6
|
作者
Alharbi, Talal [1 ]
Portmann, Marius [2 ]
机构
[1] Majmaah Univ, Coll Comp & Informat Sci, Dept Informat Technol, Al Majmaah 11952, Saudi Arabia
[2] Univ Queensland, Sch Informat Technol & Elect Engn, Brisbane, Qld 4072, Australia
来源
IEEE ACCESS | 2019年 / 7卷
关键词
Software defined network; SDN; network virtualization; security; ONOS; FlowVisor; openVirteX; SDN; IMPLEMENTATION; INTERNET;
D O I
10.1109/ACCESS.2019.2918101
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) is a new networking paradigm with the promise to increase simplicity and efficiency in network management through the separation of control functions from the forwarding functions. In SDN, the control functions are softwarized and logically placed in a centralized entity, i.e. the SDN controller. Network virtualization is one of the key features enabled and facilitated by the SDN, and it allows multiple virtual networks and the SDN controllers to share the same physical network infrastructure. This paper discusses the security of virtualization in the SDN, and it highlights and demonstrates critical vulnerabilities of key network hypervisors used in the SDN. In particular, the paper demonstrates how the isolation of different virtual networks can be broken, and enabling different types of attacks. Finally, the paper discusses the potential impact of these vulnerabilities and points to mitigation approaches.
引用
收藏
页码:66584 / 66594
页数:11
相关论文
共 50 条
  • [1] Security and performance of software-defined networks and functions virtualization
    Hausheer, David
    Hohlfeld, Oliver
    Schmid, Stefan
    Gu, Guofei
    [J]. COMPUTER NETWORKS, 2018, 138 : 15 - 17
  • [2] SECURITY FUNCTION VIRTUALIZATION IN SOFTWARE DEFINED INFRASTRUCTURE
    Yasrebi, Pouya
    Monfared, Sina
    Bannazadeh, Hadi
    Leon-Garcia, Alberto
    [J]. PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 778 - 781
  • [3] Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
    Lin, Zhaowen
    Tao, Dan
    Wang, Zhenji
    [J]. SENSORS, 2017, 17 (04)
  • [4] Telecom Software, Network Virtualization, and Software Defined Networks
    Cerroni, Walter
    Galis, Alex
    Shiomoto, Kohei
    Zhani, Mohamed Faten
    [J]. IEEE Communications Magazine, 2019, 57 (05):
  • [5] TELECOM SOFTWARE, NETWORK VIRTUALIZATION, AND SOFTWARE DEFINED NETWORKS
    Cerroni, Walter
    Galis, Alex
    Shiomoto, Kohei
    Zhani, Mohamed Faten
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2019, 57 (05) : 88 - 88
  • [6] Telecom Software, Network Virtualization, and Software Defined Networks
    Cerroni, Walter
    Galis, Alex
    Shiomoto, Kohei
    Zhani, Mohamed Faten
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2020, 58 (04) : 16 - 17
  • [7] Telecom Software, Network Virtualization, and Software Defined Networks
    Cerroni, Walter
    Galis, Alex
    Shiomoto, Kohei
    Zhani, Mohamed Faten
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2020, 58 (07) : 42 - 43
  • [8] Telecom Software, Network Virtualization, and Software Defined Networks
    Cerroni, Walter
    Galis, Alex
    Shiomoto, Kohei
    Zhani, Mohamed Faten
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2019, 57 (10) : 40 - 41
  • [9] Software Defined Networking and Virtualization for Broadband Satellite Networks
    Bertaux, Lionel
    Medjiah, Samir
    Berthou, Pascal
    Abdellatif, Slim
    Hakiri, Akram
    Gelard, Patrick
    Planchou, Fabrice
    Bruyere, Marc
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (03) : 54 - 60
  • [10] Scalable Network Virtualization in Software-Defined Networks
    Drutskoy, Dmitry
    Keller, Eric
    Rexford, Jennifer
    [J]. IEEE INTERNET COMPUTING, 2013, 17 (02) : 20 - 27