Challenges and Preparedness of SDN-based Firewalls

被引:10
|
作者
Dixit, Vaibhav Hemant [1 ]
Kyung, Sukwha [1 ]
Zhao, Ziming [1 ]
Doupe, Adam [1 ]
Shoshitaishvili, Yan [1 ]
Ahn, Gail-Joon [1 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
基金
美国国家科学基金会;
关键词
D O I
10.1145/3180465.3180468
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software-Defined Network (SDN) is a novel architecture created to address the issues of traditional and vertically integrated networks. To increase cost-effectiveness and enable logical control, SDN provides high programmability and centralized view of the network through separation of network traffic delivery (the "data plane") from network configuration (the "control plane"). SDN controllers and related protocols are rapidly evolving to address the demands for scaling in complex enterprise networks. Because of the evolution of modern SDN technologies, production networks employing SDN are prone to several security vulnerabilities. The rate at which SDN frameworks are evolving continues to overtake attempts to address their security issues. According to our study, existing defense mechanisms, particularly SDN-based firewalls, face new and SDN-specific challenges in successfully enforcing security policies in the underlying network. In this paper, we identify problems associated with SDN-based firewalls, such as ambiguous flow path calculations and poor scalability in large networks. We survey existing SDN-based firewall designs and their shortcomings in protecting a dynamically scaling network like a data center. We extend our study by evaluating one such SDN-specific security solution called FlowGuard, and identifying new attack vectors and vulnerabilities. We also present corresponding threat detection techniques and respective mitigation strategies.
引用
收藏
页码:33 / 38
页数:6
相关论文
共 50 条
  • [1] Improved Formal Verification of SDN-Based Firewalls by Using TLA+
    Kapus, Tatjana
    IEEE ACCESS, 2023, 11 : 107126 - 107134
  • [2] Formal Verification of SDN-Based Firewalls by Using TLA&x002B;
    Kim, Young-Mi
    Kang, Miyoung
    IEEE ACCESS, 2020, 8 (08): : 52100 - 52112
  • [3] SDN-based VANETs, Security Attacks, Applications, and Challenges
    Arif, Muhammad
    Wang, Guojun
    Geman, Oana
    Balas, Valentina Emilia
    Tao, Peng
    Brezulianu, Adrian
    Chen, Jianer
    APPLIED SCIENCES-BASEL, 2020, 10 (09):
  • [4] SDN-based wireless mobile backhaul architecture: Review and challenges
    Hoang Minh Do
    Gregory, Mark A.
    Li, Shuo
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 189
  • [5] Resource Management in SDN-Based Cloud and SDN-Based Fog Computing: Taxonomy Study
    Alomari, Amirah
    Subramaniam, Shamala K.
    Samian, Normalia
    Latip, Rohaya
    Zukarnain, Zuriati
    SYMMETRY-BASEL, 2021, 13 (05):
  • [6] SDN-Based Private Interconnection
    Dolev, Shlomi
    Tzur-David, Shimrit
    2014 IEEE 13TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA 2014), 2014, : 129 - 136
  • [7] Analysis of SDN-Based Security Challenges and Solution Approaches for SDWSN Usage
    Mathebula, Ishmael
    Isong, Bassey
    Gasela, Naison
    Abu-Mahfouz, Adnan M.
    2019 IEEE 28TH INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE), 2019, : 1288 - 1293
  • [8] An SDN-based MTD model
    Yang, Yubin
    Cheng, Liming
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2019, 31 (21):
  • [9] SDN-based Security Mechanism
    Aneci, Mihai-Nicolae
    Gheorghe, Laura
    Carabas, Mihai
    Soriga, Stefan
    Somcsan, Raluca-Andrcca
    2015 14TH ROEDUNET INTERNATIONAL CONFERENCE - NETWORKING IN EDUCATION AND RESEARCH (ROEDUNET NER), 2015, : 12 - 17
  • [10] SDN-based Network Mobility
    Sornlertlamvanich, P.
    Ang-Chuan, T.
    Sae-Wong, S.
    Kamolphiwong, T.
    Kamolphiwong, S.
    2016 INTERNATIONAL SYMPOSIUM ON INTELLIGENT SIGNAL PROCESSING AND COMMUNICATION SYSTEMS (ISPACS), 2016, : 464 - 469