Security Control and Data Planes of SDN: A Comprehensive Review of Traditional, AI, and MTD Approaches to Security Solutions

被引:10
|
作者
Abdi, Abdinasir Hirsi [1 ]
Audah, Lukman [1 ,2 ]
Salh, Adeb [3 ]
Alhartomi, Mohammed A. [4 ]
Rasheed, Haroon [5 ]
Ahmed, Salman [6 ]
Tahir, Ahmed [7 ]
机构
[1] Univ Tun Hussein Onn Malaysia, Fac Elect & Elect Engn, Adv Telecommun Res Ctr ATRC, Parit Raja 86400, Malaysia
[2] Univ Tun Hussein Onn Malaysia, Fac Engn Technol, Parit Raja 86400, Malaysia
[3] Univ Tunku Abdul Rahman UTAR, Fac Informat & Commun Technol, Kampar 31900, Malaysia
[4] Univ Tabuk, Dept Elect Engn, Tabuk 71491, Saudi Arabia
[5] Bahria Univ Karachi Campus, Dept Elect Engn, Karachi 75300, Pakistan
[6] Univ Tun Hussein Onn Malaysia, Fac Elect & Elect Engn, VLSI & Embedded Technol VEST Focus Grp, Parit Raja 86400, Malaysia
[7] Somtel Telecommun Co, Engn Dept, Bosaso 25290, Bari, Somalia
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Security; Artificial intelligence; Surveys; Reviews; Protocols; Programming; IP networks; Computer security; Software defined networking; AI; control plane; cybersecurity; data plane; moving target defense; SDN security; southbound interface; traditional SDN security; MOVING TARGET DEFENSE; SOFTWARE-DEFINED NETWORKS; AUTHENTICATION; ISSUES; CLASSIFICATION; VERIFICATION; CHALLENGES; MITIGATION; ATTACKS; SERVICE;
D O I
10.1109/ACCESS.2024.3393548
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking (SDN) is a groundbreaking technology that has transformed network management significantly. By integrating data and control, SDN offers unparalleled flexibility and responsiveness, thereby overcoming the limitations of conventional network architectures. However, a centralized controller, which is a hallmark of SDN, is a double-edged security sword that offers easy control. This also becomes a dangerous point of failure for the entire network. To the best of our knowledge, this is the first comprehensive study to explore traditional-based, artificial intelligence (AI)-based, and moving target defense (MTD) approaches to securing SDN. The study begins with a survey of traditional security solutions for SDN, encompassing authentication, authorization, encryption, security protocols, firewalls, and flow verification, by addressing security threats and vulnerabilities in both data and control planes. The study then investigates the application of AI-based security solutions in an SDN environment, focusing on how Machine Learning (ML) and Deep Learning (DL) techniques are leveraged to address advanced security threats. Additionally, the survey examines MTD mechanisms within data and control plane security. Several in-depth techniques, including the randomization of Internet Protocol (IP) and Media Access Control (MAC) addresses, port numbers, and flow tables, and delving into the relationship between security threats, MTD strategies, and the specific controllers employed in experimental implementations. We utilized the widely recognized STRIDE cybersecurity framework to systematically identify and evaluate the potential threats to SDN security. Our analysis resulted in a comprehensive list of security challenges, and we propose future research directions aimed at addressing emerging threats in both the data and control planes.
引用
收藏
页码:69941 / 69980
页数:40
相关论文
共 34 条
  • [1] Security Control and Data Planes of SDN: A Comprehensive Review of Traditional, AI, and MTD Approaches to Security Solutions (vol 12, pg 69941, 2024)
    Abdi, Abdinasir Hirsi
    Audah, Lukman
    Salh, Adeb
    Alhartomi, Mohammed A.
    Rasheed, Haroon
    Ahmed, Salman
    Tahir, Ahmed
    IEEE ACCESS, 2024, 12 : 162107 - 162108
  • [2] A Survey on the Security of Stateful SDN Data Planes
    Dargahi, Tooska
    Caponi, Alberto
    Ambrosin, Moreno
    Bianchi, Giuseppe
    Conti, Mauro
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (03): : 1701 - 1725
  • [3] A Comprehensive Survey on Generative AI Solutions in IoT Security
    Delgado, Juan Luis Lopez
    Ramos, Juan Antonio Lopez
    ELECTRONICS, 2024, 13 (24):
  • [4] A comprehensive review on Smart Grid Data Security
    Tyav, Jennifer
    Tufail, Shahid
    Roy, Sukanta
    Parvez, Imtiaz
    Debnath, Anjan
    Sarwat, Arif
    SOUTHEASTCON 2022, 2022, : 8 - 15
  • [5] Enhancing security of SDN focusing on control plane and data plane
    Celesova, Barbora
    Val'ko, Jozef
    Grezo, Rudolf
    Helebrandt, Pavol
    2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,
  • [6] A Review of Solutions for SDN-Exclusive Security Issues A review and critical analysis of the existent solutions aiming to provide security against attacks inherent to SDN due to its centralised nature
    Spooner, Jakob
    Zhu, Shao Ying
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (08) : 113 - 122
  • [7] A Review of P4 Programmable Data Planes for Network Security
    Gao, Ya
    Wang, Zhenling
    MOBILE INFORMATION SYSTEMS, 2021, 2021
  • [8] A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions
    Aslan, Omer
    Aktug, Semih Serkant
    Ozkan-Okay, Merve
    Yilmaz, Abdullah Asim
    Akin, Erdal
    ELECTRONICS, 2023, 12 (06)
  • [9] A comprehensive review of security threats and solutions for the online social networks industry
    Nawaz, Naeem A.
    Ishaq, Kashif
    Farooq, Uzma
    Khalil, Amna
    Rasheed, Saim
    Abid, Adnan
    Rosdi, Fadhilah
    PEERJ COMPUTER SCIENCE, 2023, 9
  • [10] In-vehicle communication cyber security: A comprehensive review of challenges and solutions
    Gul, Batuhan
    Ertam, Fatih
    VEHICULAR COMMUNICATIONS, 2024, 50