An SDN-Based Approach to Enhance the End-to-End Security: SSL/TLS Case Study

被引:0
|
作者
Ranjbar, Alireza [1 ]
Komu, Miika [1 ]
Salmela, Patrik [1 ]
Aura, Tuomas [2 ]
机构
[1] Ericsson Res, Helsinki, Finland
[2] Aalto Univ, Espoo, Finland
关键词
Software-Defined Networking; SSL/TLS; Centralized policy management; Handshake analysis; Flow verification;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
End-to-end encryption is becoming the norm for many applications and services. While this improves privacy of individuals and organizations, the phenomenon also raises new kinds of challenges. For instance, with the increase of devices using encryption, the volumes of outdated, exploitable encryption software also increases. This may create some distrust amongst the users against security unless its quality is enforced in some ways. Unfortunately, deploying new mechanisms at the end-points of the communication is challenging due to the sheer volume of devices, and modifying the existing services may not be feasible either. Hence, we propose a novel method for improving the quality of the secure sessions in a centralized way based on the SDN architecture. Instead of inspecting the encrypted traffic, our approach enhances the quality of secure sessions by analyzing the plaintext handshake messages exchanged between a client and server. We exploit the fact that many of today's security protocols negotiate the security parameters such as the protocol version, encryption algorithms or certificates in plaintext in a protocol handshake before establishing a secure session. By verifying the negotiated information in the handshake, our solution can improve the security level of SSL/TLS sessions. While the approach can be extended to many other protocols, we focus on the SSL/TLS protocol in this paper because of its wide-spread use. We present our implementation for the OpenDaylight controller and evaluate its overhead to SSL/TLS session establishment in terms of latency.
引用
收藏
页码:281 / 288
页数:8
相关论文
共 50 条
  • [1] An SDN-based true end-to-end TCP for wireless LAN
    Singh, Krishna Vijay Kumar
    Pandey, Mayank
    WIRELESS NETWORKS, 2021, 27 (02) : 1413 - 1430
  • [2] An SDN-based true end-to-end TCP for wireless LAN
    Krishna Vijay Kumar Singh
    Mayank Pandey
    Wireless Networks, 2021, 27 : 1413 - 1430
  • [3] SDN-based End-to-End Flow Control in Mobile Slice Environments
    Meneses, Flavio
    Corujo, Daniel
    Neto, Augusto
    Aguiar, Rui L.
    2018 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2018,
  • [4] Virtualized SDN-Based End-To-End Reference Architecture for Fog Networking
    Habibi, Pooyan
    Baharlooei, Soroush
    Farhoudi, Mohammd
    Kazemian, Sepehr
    Khorsandi, Siavash
    2018 32ND INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS (WAINA), 2018, : 61 - 66
  • [5] An SDN-based NAT Traversal Mechanism for End-to-end IoT Networking
    Wang, Hsu-Chien
    Chen, Chien
    Lu, Ssu-Hsuan
    2019 20TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2019,
  • [6] SDN-based architecture for end-to-end path provisioning in the mixed circuit and packet network environment
    Baik, Seongbok
    Hwang, Chankyou
    Lee, Youngwoo
    2014 16TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2014,
  • [7] End-to-end security implementation for mobile devices using TLS protocol
    Kayayurt, Baris
    Tuglular, Tugkan
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2006, 2 (01): : 87 - 97
  • [8] End-to-end security implementation for mobile devices using TLS protocol
    Baris Kayayurt
    Tugkan Tuglular
    Journal in Computer Virology, 2006, 2 (1): : 87 - 97
  • [9] An SDN-based Integration of Green TWDM-PONs and Metro Networks Preserving End-to-End Delay
    Kondepu, K.
    Sgambelluri, A.
    Valcarenghi, L.
    Cugini, F.
    Castoldi, P.
    2015 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION (OFC), 2015,
  • [10] Integrated transport layer security: End-to-end security model between WTLS and TLS
    Kwon, EK
    Cho, YG
    Chae, KJ
    15TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING, PROCEEDINGS, 2001, : 65 - 71