The (In)Security of Virtualization in Software Defined Networks

被引:6
|
作者
Alharbi, Talal [1 ]
Portmann, Marius [2 ]
机构
[1] Majmaah Univ, Coll Comp & Informat Sci, Dept Informat Technol, Al Majmaah 11952, Saudi Arabia
[2] Univ Queensland, Sch Informat Technol & Elect Engn, Brisbane, Qld 4072, Australia
来源
IEEE ACCESS | 2019年 / 7卷
关键词
Software defined network; SDN; network virtualization; security; ONOS; FlowVisor; openVirteX; SDN; IMPLEMENTATION; INTERNET;
D O I
10.1109/ACCESS.2019.2918101
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) is a new networking paradigm with the promise to increase simplicity and efficiency in network management through the separation of control functions from the forwarding functions. In SDN, the control functions are softwarized and logically placed in a centralized entity, i.e. the SDN controller. Network virtualization is one of the key features enabled and facilitated by the SDN, and it allows multiple virtual networks and the SDN controllers to share the same physical network infrastructure. This paper discusses the security of virtualization in the SDN, and it highlights and demonstrates critical vulnerabilities of key network hypervisors used in the SDN. In particular, the paper demonstrates how the isolation of different virtual networks can be broken, and enabling different types of attacks. Finally, the paper discusses the potential impact of these vulnerabilities and points to mitigation approaches.
引用
收藏
页码:66584 / 66594
页数:11
相关论文
共 50 条
  • [41] Balanced Service Chaining in Software-Defined Networks with Network Function Virtualization
    Lin, Po-Ching
    Lin, Ying-Dar
    Wu, Cheng-Ying
    Lai, Yuan-Cheng
    Kao, Yi-Chih
    [J]. COMPUTER, 2016, 49 (11) : 68 - 76
  • [42] Container-based Network Function Virtualization for Software-Defined Networks
    Cziva, Richard
    Jouet, Simon
    White, Kyle J. S.
    Pezaros, Dimitrios P.
    [J]. 2015 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2015, : 415 - 420
  • [43] Jointly optimized QoS-aware virtualization and routing in software defined networks
    Lin, Shih-Chun
    Wang, Pu
    Luo, Min
    [J]. COMPUTER NETWORKS, 2016, 96 : 69 - 78
  • [44] Network Function Virtualization as a Service for Multi-Tenant Software Defined Networks
    Ledjiar, Abderrahmane
    Sampin, Emmanuel
    Talhi, Chamseddine
    Cheriet, Mohamed
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 168 - 173
  • [45] Software defined networking and network function virtualization
    Gladisch, Andreas
    Kellerer, Wolfgang
    [J]. IT-INFORMATION TECHNOLOGY, 2015, 57 (05): : 265 - 266
  • [46] Software Defined Virtualization Platform based on Double-FlowVisors in Multiple domain Networks
    Yin, Xingbin
    Huang, Shanguo
    Wang, Shouyu
    Wu, Di
    Gao, Yuming
    Niu, Xiaobing
    Ren, Mingyan
    Ma, Heng
    [J]. 2013 8TH INTERNATIONAL ICST CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA (CHINACOM), 2013, : 776 - 780
  • [47] QoS-Aware Virtualization-Enabled Routing in Software-Defined Networks
    Porxas, Alba Xifra
    Lin, Shih-Chun
    Luo, Min
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2015, : 5771 - 5776
  • [48] On the Feasibility of Using Hierarchical Task Networks and Network Functions Virtualization for Managing Software-Defined Networks
    Villota, William
    Gironza, Mario
    Ordonez, Armando
    Rendon, Oscar Mauricio Caicedo
    [J]. IEEE ACCESS, 2018, 6 : 38026 - 38040
  • [49] DELTA: A Security Assessment Framework for Software-Defined Networks
    Lee, Seungsoo
    Yoon, Changhoon
    Lee, Chanhee
    Shin, Seungwon
    Yegneswaran, Vinod
    Porras, Phillip
    [J]. 24TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2017), 2017,
  • [50] Deep learning for the security of software-defined networks: a review
    Roya Taheri
    Habib Ahmed
    Engin Arslan
    [J]. Cluster Computing, 2023, 26 : 3089 - 3112