Repoxy: Replication Proxy for Trustworthy SDN Controller Operation

被引:3
|
作者
Azab, Mohamed [1 ]
Hamdy, Ahmed [2 ]
Mansour, Ahmed [3 ]
机构
[1] City Sci Res & Technol Applicat, Informat Res Inst, Alexandria, Egypt
[2] Fac Engn, Dept Comp & Commun Engn, Alexandria, Egypt
[3] Fac Engn, Dept Elect & Commun, Alexandria, Egypt
关键词
Software-Defined Networks; OpenFlow; Intrusion Detection; Forensic Analysis; Proxy;
D O I
10.1109/TrustCom/BigDataSE.2018.00019
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networks (SDN) is envisaged as a future model for large-scale, elastic, and adaptive networks. However, such flexibility comes with a major cost. Relying heavily on software across the entire architecture and the centralized nature of the most important component, the controller, gave the attackers asymmetric advantage. for decades, we used to build security tools to secure the network traffic, but network components security was always protected by physical perimeters behind doors. In this paper, we present REPlication prOXY(Repoxy), a smart gateway isolating the north and southbound to enhance controller resilience, availability, and reliability in presence of attacks and also discuss our first version of the implementation. Repoxy presents a novel SDN-controller intrusion detection system to detect any malicious manipulations to the controller software. Further, Repoxy enables elasticity and high-availability for SDN controllers by facilitating southbound-oblivious seamless multi-controller replication, and handover for same network traffic. Additionally, Repoxy helps forensic analysts to easily find attack traces by exploiting Repoxy's information-rich database logging all the switch controller interactions. Results and evaluations showed the enhanced trustworthiness in the SDN network with a reasonable overhead when Repoxy is used.
引用
收藏
页码:55 / 60
页数:6
相关论文
共 50 条
  • [1] Proxy SDN Controller for Wireless Networks
    Kim, Won-Suk
    Chung, Sang-Hwa
    MOBILE INFORMATION SYSTEMS, 2016, 2016
  • [2] Towards Blockchain-based Multi-controller Managed Switching for Trustworthy SDN Operation
    Azab, Mohamed
    Ergawy, Rana R.
    Ghourab, Esraa M.
    Mokhtar, Amr
    Rizk, Mohamed
    2019 IEEE 10TH ANNUAL INFORMATION TECHNOLOGY, ELECTRONICS AND MOBILE COMMUNICATION CONFERENCE (IEMCON), 2019, : 991 - 998
  • [3] Controller Backup and Replication for Reliable Multi-domain SDN
    Mao, Junli
    Chen, Lishui
    Li, Jiacong
    Ge, Yi
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2020, 14 (12): : 4725 - 4747
  • [4] Controller scheduling for continued SDN operation under DDoS attacks
    Lim, Sungheon
    Yang, Seungnam
    Kim, Younghwa
    Yang, Sunhee
    Kim, Hyogon
    ELECTRONICS LETTERS, 2015, 51 (16) : 1259 - 1260
  • [5] An Optical SDN Controller for Transport Network Virtualization and Autonomic Operation
    Siqueira, Marcos
    Oliveira, Juliano
    Curiel, Giovanni
    Hirata, Alberto
    van't Hooft, Fabian
    Nascimento, Marcelo
    Oliveira, Julio
    Rothenberg, Christian Esteve
    2013 IEEE GLOBECOM WORKSHOPS (GC WKSHPS), 2013, : 1198 - 1203
  • [6] Controller-proxy: Scaling network management for large-scale SDN networks
    Song, Ping
    Liu, Yi
    Liu, Tianxiao
    Qian, Depei
    COMPUTER COMMUNICATIONS, 2017, 108 : 52 - 63
  • [7] LoCoSDN: A Local Controller for Operation of OF Switches in non-SDN Networks
    Schmidt, Mark
    Hauser, Frederik
    Germann, Bastian
    Menth, Michael
    2018 FIFTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2018, : 80 - 86
  • [8] Persistent Store-based Dual Replication System for Distributed SDN Controller
    Han, Sangyun
    Lee, Sungwon
    2016 INTERNATIONAL CONFERENCE ON SELECTED TOPICS IN MOBILE & WIRELESS NETWORKING (MOWNET), 2016, : 141 - 142
  • [9] Resource-saving Replication for Controllers in Multi-controller SDN against Network Failures
    Zhang, Lingyu
    Wang, Ying
    Zhong, Xuxia
    Li, Wenjing
    Guo, Shaoyong
    NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,
  • [10] Trustworthy Enhancement for Cloud Proxy based on Autonomic Computing
    He, Hui
    Zhang, Weizhe
    Liu, Chuanyi
    Sun, Honglei
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2020, 8 (04) : 1108 - 1121