On the Design and Implementation of a Security Architecture for Software Defined Networks

被引:0
|
作者
Karmakar, Kallol Krishna [1 ]
Varadharajan, Vijay [1 ]
Tupakula, Udaya [1 ]
机构
[1] Macquarie Univ, Fac Sci, Adv Cyber Secur Res Ctr, Sydney, NSW, Australia
来源
PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS) | 2016年
关键词
Software Defined Networking (SDN) Security; OpenFlow; ACL; Source Spoofing; Policy Control;
D O I
10.1109/HPCC-SmartCity-DSS.2016.138
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose techniques for securing Software Defined Networks(SDN). We describe the design of a security architecture that makes use of security applications on top of the SDN Controller to specify fine granular security policies based on domain wide knowledge of the domain and Security Agents to enforce these policies in the switches in the data plane. We have extended the Open Flow protocol to enable communication of the security policies between the security applications in the Controller to the agents in the switches. We have implemented the security architecture using POX Controller and demonstrated the operation of our architecture in a range of scenarios such as enforcing specific security policies for different traffic with different services, counteracting attacks such as Heartbleed and Shellshock as well as spoofing attacks, and protecting Content Management Systems(CMS) from data confidentiality attacks.
引用
收藏
页码:671 / 678
页数:8
相关论文
共 50 条
  • [11] Scheduling of Security Resources in Software Defined Security Architecture
    Zhang, Gang
    Qiu, Xiaofeng
    Chang, Wei
    2017 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC), 2017, : 494 - 503
  • [12] The Design and Implementation of Software Defined Network Security Service Choreography System
    Ye, Zhiyuan
    Cao, Can
    Wang, Lei
    2022 6TH INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE AND INTELLIGENT CONTROL, ISCSIC, 2022, : 25 - 29
  • [13] Design and Implementation of Programmable Nodes in Software Defined Sensor Networks
    Ding, Cui
    Shen, Lianfeng
    2017 IEEE 85TH VEHICULAR TECHNOLOGY CONFERENCE (VTC SPRING), 2017,
  • [14] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [15] A Survey of Security in Software Defined Networks
    Scott-Hayward, Sandra
    Natarajan, Sriram
    Sezer, Sakir
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2016, 18 (01): : 623 - 654
  • [16] Security of Software Defined Networks: A survey
    Alsmadr, Izzat
    Xu, Dianxiang
    COMPUTERS & SECURITY, 2015, 53 : 79 - 108
  • [17] Security in Software Defined Networks: A Survey
    Ahmad, Ijaz
    Namal, Suneth
    Ylianttila, Mika
    Gurtov, Andrei
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04): : 2317 - 2346
  • [18] The (In)Security of Virtualization in Software Defined Networks
    Alharbi, Talal
    Portmann, Marius
    IEEE ACCESS, 2019, 7 : 66584 - 66594
  • [19] An Architecture for Software Defined Drone Networks
    Alharthi, Mohannad
    Taha, Abd-Elhamid M.
    Hassanein, Hossam S.
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [20] A Security Controller-based Software Defined Security Architecture
    Qiu, Xiaofeng
    Cheng, Fangyuan
    Wang, Weijia
    Zhang, Gang
    Qiu, Yangjun
    PROCEEDINGS OF THE 2017 20TH CONFERENCE ON INNOVATIONS IN CLOUDS, INTERNET AND NETWORKS (ICIN), 2017, : 191 - 195