Challenges and Preparedness of SDN-based Firewalls

被引:10
|
作者
Dixit, Vaibhav Hemant [1 ]
Kyung, Sukwha [1 ]
Zhao, Ziming [1 ]
Doupe, Adam [1 ]
Shoshitaishvili, Yan [1 ]
Ahn, Gail-Joon [1 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
基金
美国国家科学基金会;
关键词
D O I
10.1145/3180465.3180468
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software-Defined Network (SDN) is a novel architecture created to address the issues of traditional and vertically integrated networks. To increase cost-effectiveness and enable logical control, SDN provides high programmability and centralized view of the network through separation of network traffic delivery (the "data plane") from network configuration (the "control plane"). SDN controllers and related protocols are rapidly evolving to address the demands for scaling in complex enterprise networks. Because of the evolution of modern SDN technologies, production networks employing SDN are prone to several security vulnerabilities. The rate at which SDN frameworks are evolving continues to overtake attempts to address their security issues. According to our study, existing defense mechanisms, particularly SDN-based firewalls, face new and SDN-specific challenges in successfully enforcing security policies in the underlying network. In this paper, we identify problems associated with SDN-based firewalls, such as ambiguous flow path calculations and poor scalability in large networks. We survey existing SDN-based firewall designs and their shortcomings in protecting a dynamically scaling network like a data center. We extend our study by evaluating one such SDN-specific security solution called FlowGuard, and identifying new attack vectors and vulnerabilities. We also present corresponding threat detection techniques and respective mitigation strategies.
引用
收藏
页码:33 / 38
页数:6
相关论文
共 50 条
  • [21] SDN-based Stateful Firewall for Cloud
    Li, Jian
    Jiang, Hao
    Jiang, Wei
    Wu, Jing
    Du, Wen
    2020 IEEE 6TH INT CONFERENCE ON BIG DATA SECURITY ON CLOUD (BIGDATASECURITY) / 6TH IEEE INT CONFERENCE ON HIGH PERFORMANCE AND SMART COMPUTING, (HPSC) / 5TH IEEE INT CONFERENCE ON INTELLIGENT DATA AND SECURITY (IDS), 2020, : 157 - 161
  • [22] SDN-Based Secure Architecture for IoT
    Mishra, Shailendra
    INTERNATIONAL JOURNAL OF KNOWLEDGE AND SYSTEMS SCIENCE, 2020, 11 (04) : 1 - 16
  • [23] Evaluation of an SDN-based Microservice Architecture
    Holscher, Anton
    Asplund, Mikael
    Boeira, Felipe
    PROCEEDINGS OF THE 2022 IEEE 8TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2022): NETWORK SOFTWARIZATION COMING OF AGE: NEW CHALLENGES AND OPPORTUNITIES, 2022, : 151 - 156
  • [24] SDN-based Handover in Future WLAN
    Gilani, Syed Mushhad M.
    Jin, Wenqiang
    Hong, Tang
    Zhao, Guofeng
    Xu, Chuan
    INTERNATIONAL JOURNAL OF FUTURE GENERATION COMMUNICATION AND NETWORKING, 2016, 9 (12): : 139 - 153
  • [25] SDN-Based Active Content Networking
    Um, Tai-Won
    Lee, Gyu Myoung
    Kim, Jinsul
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2016,
  • [26] μSDN: An SDN-based Routing Architecture for Wireless Sensor Networks
    da Silva Santos, Leonardo Francisco
    de Mendonca Junior, Francisco Ferreira
    Dias, Kelvin Lopes
    2017 VII BRAZILIAN SYMPOSIUM ON COMPUTING SYSTEMS ENGINEERING (SBESC), 2017, : 63 - 70
  • [27] Security of SDN-based vehicular ad hoc networks: State-of-the-art and challenges
    Sultana, Rukhsar
    Grover, Jyoti
    Tripathi, Meenakshi
    VEHICULAR COMMUNICATIONS, 2021, 27
  • [28] Probe-SDN: a smart monitoring framework for SDN-based networks
    Henni, Djamel-Eddine
    Hadjaj-Aoul, Yassine
    Ghomari, Abdelghani
    2016 GLOBAL INFORMATION INFRASTRUCTURE AND NETWORKING SYMPOSIUM (GIIS), 2016,
  • [29] HiQoS:An SDN-Based Multipath QoS Solution
    YAN Jinyao
    ZHANG Hailong
    SHUAI Qianjun
    LIU Bo
    GUO Xiao
    中国通信, 2015, 12 (05) : 123 - 133
  • [30] SDN-Based Broadband Network for Cloud Services
    Xiongyan Tang
    Pei Zhang
    Chang Cao
    ZTE Communications, 2014, 12 (02) : 18 - 22