Challenges and Preparedness of SDN-based Firewalls

被引:10
|
作者
Dixit, Vaibhav Hemant [1 ]
Kyung, Sukwha [1 ]
Zhao, Ziming [1 ]
Doupe, Adam [1 ]
Shoshitaishvili, Yan [1 ]
Ahn, Gail-Joon [1 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
基金
美国国家科学基金会;
关键词
D O I
10.1145/3180465.3180468
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software-Defined Network (SDN) is a novel architecture created to address the issues of traditional and vertically integrated networks. To increase cost-effectiveness and enable logical control, SDN provides high programmability and centralized view of the network through separation of network traffic delivery (the "data plane") from network configuration (the "control plane"). SDN controllers and related protocols are rapidly evolving to address the demands for scaling in complex enterprise networks. Because of the evolution of modern SDN technologies, production networks employing SDN are prone to several security vulnerabilities. The rate at which SDN frameworks are evolving continues to overtake attempts to address their security issues. According to our study, existing defense mechanisms, particularly SDN-based firewalls, face new and SDN-specific challenges in successfully enforcing security policies in the underlying network. In this paper, we identify problems associated with SDN-based firewalls, such as ambiguous flow path calculations and poor scalability in large networks. We survey existing SDN-based firewall designs and their shortcomings in protecting a dynamically scaling network like a data center. We extend our study by evaluating one such SDN-specific security solution called FlowGuard, and identifying new attack vectors and vulnerabilities. We also present corresponding threat detection techniques and respective mitigation strategies.
引用
收藏
页码:33 / 38
页数:6
相关论文
共 50 条
  • [41] A SDN-based Aeronautical Communications Network Architecture
    Hu, Yim-Fun
    Ali, Muhammad
    Doanh Luong
    Abdo, Kanaan
    Cormbe, Quentin
    Barossi, Regis
    BenSlama, Fathia
    Benamrane, Fouad
    2018 IEEE/AIAA 37TH DIGITAL AVIONICS SYSTEMS CONFERENCE (DASC), 2018, : 753 - 762
  • [42] SDN-based solutions to Improve IOT: Survey
    Zemrane, Hamza
    Baddi, Youssef
    Hasbi, Abderrahim
    2018 IEEE 5TH INTERNATIONAL CONGRESS ON INFORMATION SCIENCE AND TECHNOLOGY (IEEE CIST'18), 2018, : 588 - 593
  • [43] SDN-based hybrid honeypot for attack capture
    Wang, He
    Wu, Bin
    PROCEEDINGS OF 2019 IEEE 3RD INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2019), 2019, : 1602 - 1606
  • [44] Bulk Restoration for SDN-Based Transport Network
    Zhao, Yang
    Wang, Lei
    Chen, Xue
    Yang, Futao
    SCIENTIFIC PROGRAMMING, 2016, 2016
  • [45] Dynamic Failover for SDN-based Virtual Networks
    Ko, Kyungchan
    Son, Dongho
    Hyun, Jonghwan
    Li, Jian
    Han, Yoonseon
    Hong, James Won-Ki
    2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [46] Handover Management in SDN-based Mobile Networks
    Kuklinski, Slawomir
    Li, Yuhong
    Khoa Truong Dinh
    2014 GLOBECOM WORKSHOPS (GC WKSHPS), 2014, : 194 - 200
  • [47] A SDN-based network architecture for cloud resiliency
    Fressancourt, Antoine
    Gagnaire, Maurice
    2015 12TH ANNUAL IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, 2015, : 479 - 484
  • [48] Resilient SDN-Based Communication in Vehicular Network
    Kalokhe, Kamran Naseem
    Park, Younghee
    Chang, Sang-Yoon
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS (WASA 2018), 2018, 10874 : 865 - 873
  • [49] An SDN-based Architecture for Network-as-a-Service
    Manthena, Mani Prashanth Varma
    van Adrichem, Niels L. M.
    van den Broek, Casper
    Kuipers, Fernando
    2015 1ST IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT), 2015,
  • [50] On SDN-Based Extreme-Scale Networks
    Ghalwash, Haitham
    Huang, Chun-Hsi
    2016 IEEE HIGH PERFORMANCE EXTREME COMPUTING CONFERENCE (HPEC), 2016,