Challenges and Preparedness of SDN-based Firewalls

被引:10
|
作者
Dixit, Vaibhav Hemant [1 ]
Kyung, Sukwha [1 ]
Zhao, Ziming [1 ]
Doupe, Adam [1 ]
Shoshitaishvili, Yan [1 ]
Ahn, Gail-Joon [1 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
基金
美国国家科学基金会;
关键词
D O I
10.1145/3180465.3180468
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software-Defined Network (SDN) is a novel architecture created to address the issues of traditional and vertically integrated networks. To increase cost-effectiveness and enable logical control, SDN provides high programmability and centralized view of the network through separation of network traffic delivery (the "data plane") from network configuration (the "control plane"). SDN controllers and related protocols are rapidly evolving to address the demands for scaling in complex enterprise networks. Because of the evolution of modern SDN technologies, production networks employing SDN are prone to several security vulnerabilities. The rate at which SDN frameworks are evolving continues to overtake attempts to address their security issues. According to our study, existing defense mechanisms, particularly SDN-based firewalls, face new and SDN-specific challenges in successfully enforcing security policies in the underlying network. In this paper, we identify problems associated with SDN-based firewalls, such as ambiguous flow path calculations and poor scalability in large networks. We survey existing SDN-based firewall designs and their shortcomings in protecting a dynamically scaling network like a data center. We extend our study by evaluating one such SDN-specific security solution called FlowGuard, and identifying new attack vectors and vulnerabilities. We also present corresponding threat detection techniques and respective mitigation strategies.
引用
收藏
页码:33 / 38
页数:6
相关论文
共 50 条
  • [31] Performance Assessment for different SDN-Based Controllers
    Sheikh, Mohammad Nowsin Amin
    Hwang, I-Shyan
    Ganesan, Elaiyasuriyan
    Kharga, Razat
    2021 30TH WIRELESS AND OPTICAL COMMUNICATIONS CONFERENCE (WOCC 2021), 2021, : 24 - 25
  • [32] ZOOM: Lightweight SDN-based Elephant Detection
    Gebert, Steffen
    Geissler, Stefan
    Zinner, Thomas
    Ahn Nguyen-Ngoc
    Lange, Stanislav
    Phuoc Tran-Gia
    2016 28TH INTERNATIONAL TELETRAFFIC CONGRESS (ITC 28), VOL 2, 2016, : 1 - 6
  • [33] SDN-based SYN Flooding Defense in Cloud
    Mahrach, Safaa
    El Mir, Iman
    Haqiq, Abdelkrim
    Huang, Dijiang
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2018, 13 (01): : 30 - 39
  • [34] SDN-based management of heterogeneous home networks
    Soetens, Niels
    Famaey, Jeroen
    Verstappen, Matthias
    Latre, Steven
    2015 11TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2015, : 402 - 405
  • [35] SDN-Based Service Delivery in Smart Environments
    Ribeiro Arbiza, Lucas Mendes
    Rockenbach Tarouco, Liane Margarida
    Bertholdo, Leandro Marcio
    Granville, Lisandro Zambenedetti
    INTELLIGENT DISTRIBUTED COMPUTING IX, IDC'2015, 2016, 616 : 475 - 484
  • [36] Explainable Security in SDN-Based IoT Networks
    Sarica, Alper Kaan
    Angin, Pelin
    SENSORS, 2020, 20 (24) : 1 - 30
  • [37] A Framework for Security Enhancement in SDN-based Datacenters
    Ammar, Moustafa
    Rizk, Mohamed
    Abdel-Hamid, Ayman
    Aboul-Seoud, Ahmed K.
    2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [38] SDN-based Regulated Flow Routing in MANETs
    Streit, Klement
    Schmitt, Corinna
    Giannelli, Carlo
    2020 IEEE INTERNATIONAL CONFERENCE ON SMART COMPUTING (SMARTCOMP), 2020, : 73 - 80
  • [39] Securing SDN-Based IoT Group Communication
    Alzahrani, Bander
    Fotiou, Nikos
    FUTURE INTERNET, 2021, 13 (08):
  • [40] Research on SDN-based LP production model
    Chen, Li
    Xu, Fuyan
    Zhang, Xinrui
    Han, Haijing
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND ENGINEERING MANAGEMENT, 2008, : 317 - 321