On the Design and Implementation of a Security Architecture for Software Defined Networks

被引:0
|
作者
Karmakar, Kallol Krishna [1 ]
Varadharajan, Vijay [1 ]
Tupakula, Udaya [1 ]
机构
[1] Macquarie Univ, Fac Sci, Adv Cyber Secur Res Ctr, Sydney, NSW, Australia
来源
PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS) | 2016年
关键词
Software Defined Networking (SDN) Security; OpenFlow; ACL; Source Spoofing; Policy Control;
D O I
10.1109/HPCC-SmartCity-DSS.2016.138
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose techniques for securing Software Defined Networks(SDN). We describe the design of a security architecture that makes use of security applications on top of the SDN Controller to specify fine granular security policies based on domain wide knowledge of the domain and Security Agents to enforce these policies in the switches in the data plane. We have extended the Open Flow protocol to enable communication of the security policies between the security applications in the Controller to the agents in the switches. We have implemented the security architecture using POX Controller and demonstrated the operation of our architecture in a range of scenarios such as enforcing specific security policies for different traffic with different services, counteracting attacks such as Heartbleed and Shellshock as well as spoofing attacks, and protecting Content Management Systems(CMS) from data confidentiality attacks.
引用
收藏
页码:671 / 678
页数:8
相关论文
共 50 条
  • [41] Load Balancing Implementation in Software Defined Networks
    Prodanov, Nikolay S.
    Nikolova, Kamelia S.
    Atamian, Dimitar K.
    2022 57TH INTERNATIONAL SCIENTIFIC CONFERENCE ON INFORMATION, COMMUNICATION AND ENERGY SYSTEMS AND TECHNOLOGIES (ICEST), 2022, : 72 - 75
  • [42] Software-defined security architecture for a smart home networks using token sharing mechanism
    Saxena, Utkarsh
    Sodhi, J.S.
    Singh, Yaduveer
    Recent Advances in Computer Science and Communications, 2021, 14 (05): : 1658 - 1668
  • [43] Extended data plane architecture for in-network security services in software-defined networks
    Kim, Jinwoo
    Kim, Yeonkeun
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    Park, Taejune
    COMPUTERS & SECURITY, 2023, 124
  • [44] Improving the Routing Security in Software-Defined Networks
    Ai, Jianjian
    Guo, Zehua
    Chen, Hongchang
    Cheng, Guozhen
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (05) : 838 - 841
  • [45] Software Defined Wireless Sensor Networks Security Challenges
    Kgogo, Tebogo
    Isong, Bassey
    Abu-Mahfouz, Adnan M.
    2017 IEEE AFRICON, 2017, : 1508 - 1513
  • [46] Cognition: A tool for reinforcing security in software defined networks
    Tantar, Emilia
    Palattella, Maria Rita
    Avanesov, Tigran
    Kantor, Miroslaw
    Engel, Thomas
    Advances in Intelligent Systems and Computing, 2014, 288 : 61 - 78
  • [47] Software Defined Security for Vehicular Ad Hoc Networks
    Kalinin, Maxim
    Zegzhda, Peter
    Zegzhda, Dmitry
    Vasiliev, Yuri
    Belenko, Viacheslav
    2016 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC 2016): TOWARDS SMARTER HYPER-CONNECTED WORLD, 2016, : 533 - 537
  • [48] Semantic Security Tools in Software-Defined Networks
    Antoshina, E. Ju.
    Chalyy, D. Ju.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2018, 52 (07) : 605 - 607
  • [49] Software Defined Networking Architecture, Security and Energy Efficiency: A Survey
    Rawat, Danda B.
    Reddy, Swetha R.
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (01): : 325 - 346
  • [50] Security Policy Transition Framework for Software Defined Networks
    Cox, Jacob H., Jr.
    Clark, Russell J.
    Owen, Henry L.
    2016 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2016, : 56 - 61