Controller-Oblivious Dynamic Access Control in Software-Defined Networks

被引:2
|
作者
Gomez, Steven R. [1 ]
Jero, Samuel [1 ]
Skowyra, Richard [1 ]
Martin, Jason [1 ]
Sullivan, Patrick [1 ]
Bigelow, David [1 ]
Ellenbogen, Zachary [1 ]
Ward, Bryan C. [1 ]
Okhravi, Hamed [1 ]
Landry, James W. [1 ]
机构
[1] MIT, Lincoln Lab, 244 Wood St, Lexington, MA 02173 USA
关键词
D O I
10.1109/DSN.2019.00053
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Conventional network access control approaches are static (e.g., user roles in Active Directory), coarse-grained (e.g., 802.1x), or both (e.g., VLANs). Such systems are unable to meaningfully stop or hinder motivated attackers seeking to spread throughout an enterprise network. To address this threat, we present Dynamic Flow Isolation (DFI), a novel architecture for supporting dynamic, fine-grained access control policies enforced in a Software-Defined Network (SDN). These policies can emit and revoke specific access control rules automatically in response to network events like users logging off, letting the network adaptively reduce unnecessary reachability that could be potentially leveraged by attackers. DFI is oblivious to the SDN controller implementation and processes new packets prior to the controller, making DFI's access control resilient to a malicious or faulty controller or its applications. We implemented DFI for OpenFlow networks and demonstrated it on an enterprise SDN testbed with around 100 end hosts and servers. Finally, we evaluated the performance of DFI and how it enables a novel policy, which is otherwise difficult to enforce, that protects against a surrogate of the recent NotPetya malware in an infection scenario. We found that the threat was most limited in its ability to spread using our policy, which automatically restricted network flows over the course of the attack, compared to no access control or a static role-based policy.
引用
收藏
页码:447 / 459
页数:13
相关论文
共 50 条
  • [1] Software-Defined Transceivers in Dynamic Access Networks
    Hillerkuss, David
    Leuthold, Juerg
    [J]. JOURNAL OF LIGHTWAVE TECHNOLOGY, 2016, 34 (02) : 792 - 797
  • [2] Software-Defined Transceivers for Dynamic Access Networks
    Hillerkuss, David
    Leuthold, Juerg
    [J]. 2015 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION (OFC), 2015,
  • [3] Dynamic controller assignment problem in software-defined networks
    Zhang, Bang
    Wang, Xingwei
    Huang, Min
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2018, 29 (08):
  • [4] Secure access of resources in software-defined networks using dynamic access control list
    Ramprasath, J.
    Seethalakshmi, V
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2021, 34 (01)
  • [5] Software-Defined Access Networks
    Elbers, Joerg-Peter
    Grobe, Klaus
    Magee, Anthony
    [J]. 2014 EUROPEAN CONFERENCE ON OPTICAL COMMUNICATION (ECOC), 2014,
  • [6] Software-Defined Access Networks
    Kerpez, Kenneth J.
    Cioffi, John M.
    Ginis, George
    Goldburg, Marc
    Galli, Stefano
    Silverman, Peter
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2014, 52 (09) : 152 - 159
  • [7] Dynamic slave controller assignment for enhancing control plane robustness in software-defined networks
    Hu, Tao
    Yi, Peng
    Guo, Zehua
    Lan, Julong
    Hu, Yuxiang
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 95 : 681 - 693
  • [8] Dynamic control plane management for software-defined networks
    Li, Jian
    Yoo, Jae-Hyoung
    Hong, James Won-Ki
    [J]. INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2016, 26 (02) : 111 - 130
  • [9] A Dynamic Association Strategy for Controller Load Balancing in Software-Defined Networks
    Li, Shuangqing
    Li, Zhihao
    Zhang, Weiqi
    [J]. 2022 23RD ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS 2022), 2022, : 211 - 216
  • [10] Future Scenarios for Software-Defined Metro and Access Networks and Software-Defined Photonics
    Muciaccia, Tommaso
    Passaro, Vittorio M. N.
    [J]. PHOTONICS, 2017, 4 (01)