A Formal Approach for Automatic Detection and Correction of SDN Switch Misconfigurations

被引:0
|
作者
Saied, Wejdene [1 ]
Bouhoula, Adel [2 ]
机构
[1] Univ Carthage, Digital Secur Res Lab, Sup Com, Tunis, Tunisia
[2] Arabian Gulf Univ, Coll Grad Studies, POB 26671, Manama, Bahrain
关键词
Software Defined Networking; Security Policy; Invariants Detection; Flow entries Decision Diagram; Formal Method;
D O I
10.23919/cnsm50824.2020.9269038
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) is a network architecture that enables the network to be centrally controlled using software. The network administrators can reprogram the network using SDN without changing hardware devices to provide new solutions for controlling network traffic. However, SDN has its drawbacks in security, scalability, and elasticity. The security validation of SDN configurations is an important issue that should be addressed. Therefore, there is a need for automated methods to analyze, investigate and fix switch configurations faults. The objective of our work is to propose: (1) a new formal approach to discover security challenges using Flow entries Decision Diagram (FeDD) analysis, to identify loop freedom, access violation, blackholes, and controller misconfiguration; (2) an optimal and fine-grained resolution mechanisms to correct these misconfigurations in different topologies: (3) a tool that implements the proposed techniques and effectively helps administrators in detecting and resolving switch misconfigurations.
引用
收藏
页数:5
相关论文
共 50 条
  • [1] Formal approach for managing firewall misconfigurations
    Saadaoui, Amina
    Ben Souayeh, Nihel Ben Youssef
    Bouhoula, Adel
    [J]. 2014 IEEE EIGHTH INTERNATIONAL CONFERENCE ON RESEARCH CHALLENGES IN INFORMATION SCIENCE (RCIS), 2014,
  • [2] Automatic Classification and Detection of Snort Configuration Anomalies - a Formal Approach
    Saadaoui, Amina
    Benmoussa, Hajar
    Bouhoula, Adel
    Abou EL Kalam, Anas
    [J]. INTERNATIONAL JOINT CONFERENCE: CISIS'15 AND ICEUTE'15, 2015, 369 : 27 - 39
  • [3] A Dynamic Adaptive Timeout Approach for SDN Switch
    Liu, Yang
    Tang, BiHua
    Yuan, DongMing
    Ran, Jing
    Hu, HeFei
    [J]. 2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 2577 - 2582
  • [4] Traffic-based Malicious Switch Detection in SDN
    Du, Xiaodong
    Wang, Ming-Zhong
    Zhang, Xiaoping
    Zhu, Liehuang
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (05): : 119 - 130
  • [5] FPGA-based approach for organization of SDN switch
    Kalyaev, Anatoly
    Melnik, Eduard
    [J]. 2015 9TH INTERNATIONAL CONFERENCE ON APPLICATION OF INFORMATION AND COMMUNICATION TECHNOLOGIES (AICT), 2015, : 363 - 366
  • [6] ERROR DETECTION AND CORRECTION IN FORMAL LANGUAGES
    IWAMOTO, K
    SAWANO, A
    [J]. NEC RESEARCH & DEVELOPMENT, 1973, (30): : 64 - 71
  • [7] Tango: Simplifying SDN Control with Automatic Switch Property Inference, Abstraction, and Optimization
    Lazaris, Aggelos
    Tahara, Daniel
    Huang, Xin
    Li, Li Erran
    Voellmy, Andreas
    Yang, Y. Richard
    Yu, Minlan
    [J]. PROCEEDINGS OF THE 2014 CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES (CONEXT'14), 2014, : 199 - 211
  • [8] An Improved Switch Migration Approach to Controller Load Balancing in SDN
    Hu, Tao
    Zhang, Jianhui
    Wang, Liye
    Qiao, Dan
    [J]. PROCEEDINGS OF THE 2017 2ND INTERNATIONAL SYMPOSIUM ON ADVANCES IN ELECTRICAL, ELECTRONICS AND COMPUTER ENGINEERING (ISAEECE 2017), 2017, 124 : 436 - 442
  • [9] Designing and Prototyping of SDN Switch for Application-Driven Approach
    Molinos, Diego Nunes
    Oliveira, Romerson Deiny
    Freitas, Marcelo Silva
    de Souza Neto, Natal Vieira
    de Almeida, Marcelo Barros
    Silva, Flavio de Oliveira
    Rosa, Pedro Frosi
    [J]. ADVANCED INFORMATION NETWORKING AND APPLICATIONS, AINA-2022, VOL 2, 2022, 450 : 646 - 658
  • [10] Preserving Confidentiality during the Migration of Virtual SDN Topologies: A Formal Approach
    Charmet, Fabien
    Waldinger, Richard
    Blanc, Gregory
    Kiennert, Christophe
    Toumi, Khalifa
    [J]. 2017 IEEE 16TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2017, : 453 - 457