Securing the Software-Defined Network Control Layer

被引:57
|
作者
Porras, Phillip [1 ]
Cheung, Steven [1 ]
Fong, Martin [1 ]
Skinner, Keith [1 ]
Yegneswaran, Vinod [1 ]
机构
[1] SRI Int, Comp Sci Lab, Menlo Pk, CA 94025 USA
关键词
VERIFICATION;
D O I
10.14722/ndss.2015.23222
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networks (SDNs) pose both an opportunity and challenge to the network security community. The opportunity lies in the ability of SDN applications to express intelligent and agile threat mitigation logic against hostile flows, without the need for specialized inline hardware. However, the SDN community lacks a secure control-layer to manage the interactions between the application layer and the switch infrastructure (the data plane). There are no available SDN controllers that provide the key security features, trust models, and policy mediation logic, necessary to deploy multiple SDN applications into a highly sensitive computing environment. We propose the design of security extensions at the control layer to provide the security management and arbitration of conflicting flow rules that arise when multiple applications are deployed within the same network. We present a prototype of our design as a Security Enhanced version of the widely used OpenFlow Floodlight Controller, which we call SE-Floodlight. SE-Floodlight extends Floodlight with a security-enforcement kernel (SEK) layer, whose functions are also directly applicable to other OpenFlow controllers. The SEK adds a unique set of secure application management features, including an authentication service, role-based authorization, a permission model for mediating all configuration change requests to the data-plane, inline flow-rule conflict resolution, and a security audit service. We demonstrate the robustness and scalability of our system implementation through both a comprehensive functionality assessment and a performance evaluation that illustrates its sub-linear scaling properties.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] A novel industrial control architecture based on Software-Defined Network
    Liang, Geng
    Li, Wen
    MEASUREMENT & CONTROL, 2018, 51 (7-8): : 360 - 367
  • [22] Hierarchical and Distributed Software-Defined Network to Reduce Control Load
    Ueda, Tetsuro
    Idoue, Akira
    Utsunomiya, Eiji
    2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,
  • [23] Cross-Layer Software-Defined 5G Network
    Yang, Mao
    Li, Yong
    Hu, Long
    Li, Bo
    Jin, Depeng
    Chen, Sheng
    Yan, Zhongjiang
    MOBILE NETWORKS & APPLICATIONS, 2015, 20 (03): : 400 - 409
  • [24] Programming Network via Distributed Control in Software-Defined Networks
    Zhou, Boyang
    Wu, Chunming
    Hong, Xiaoyan
    Jiang, Ming
    2014 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2014, : 3051 - 3057
  • [25] Access Control for Software-Defined Heterogeneous Wireless Access Network
    Xu, Fangmin
    Qiu, Chao
    Guo, Andong
    Zhao, Chenglin
    2016 16TH INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES (ISCIT), 2016, : 520 - 524
  • [26] On SDPN: Integrating the Software-Defined Perimeter (SDP) and the Software-Defined Network (SDN) Paradigms
    Lefebvre, Michael
    Engels, Daniel W.
    Nair, Suku
    2022 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2022, : 353 - 358
  • [27] Simulation of Network Migration to Software-Defined Network
    Rahim, Mukti
    Hikmatullah, Muhammad Rizky
    Saskara, GedeArna Jude
    Rachmana, Nana S.
    2015 9TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATION SYSTEMS SERVICES AND APPLICATIONS (TSSA), 2015,
  • [28] Securing Software-Defined WSNs Communication via Trust Management
    Bin-Yahya, Manaf
    Alhussein, Omar
    Shen, Xuemin
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (22) : 22230 - 22245
  • [29] Extending the Software-defined Network Boundary
    Michel, Oliver
    Coughlin, Michael
    Keller, Eric
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (04) : 381 - 382
  • [30] Strengthen Software-Defined Network in Cloud
    Sun, Guoyou
    Cheng, Shaoyin
    Jiang, Fan
    PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 385 - 392