OpenSec: Policy-Based Security Using Software-Defined Networking

被引:58
|
作者
Lara, Adrian [1 ]
Ramamurthy, Byrav [1 ]
机构
[1] Univ Nebraska, Dept Comp Sci & Engn, Lincoln, NE 68588 USA
基金
美国国家科学基金会;
关键词
Software-defined networking; OpenFlow; network security; policy-based network management; policy specification; MANAGEMENT;
D O I
10.1109/TNSM.2016.2517407
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the popularity of software-defined networks (SDN) and OpenFlow increases, policy-driven network management has received more attention. Manual configuration of multiple devices is being replaced by an automated approach where a software-based, network-aware controller handles the configuration of all network devices. Software applications running on top of the network controller provide an abstraction of the topology and facilitate the task of operating the network. We propose OpenSec, an OpenFlow-based security framework that allows a network security operator to create and implement security policies written in human-readable language. Using OpenSec, the user can describe a flow in terms of OpenFlow matching fields, define which security services must be applied to that flow (deep packet inspection, intrusion detection, spam detection, etc.) and specify security levels that define how OpenSec reacts if malicious traffic is detected. In this paper, we first provide a more detailed explanation of how OpenSec converts security policies into a series of OpenFlow messages needed to implement such a policy. Second, we describe how the framework automatically reacts to security alerts as specified by the policies. Third, we perform additional experiments on the GENI testbed to evaluate the scalability of the proposed framework using existing datasets of campus networks. Our results show that up to 95% of attacks in an existing data set can be detected and 99% of malicious source nodes can be blocked automatically. Furthermore, we show that our policy specification language is simpler while offering fast translation times compared to existing solutions.
引用
收藏
页码:30 / 42
页数:13
相关论文
共 50 条
  • [21] Software-defined networking
    Greene, Kate
    Technology Review, 2009, 112 (02)
  • [22] Software-Defined Networking
    Kirkpatrick, Keith
    COMMUNICATIONS OF THE ACM, 2013, 56 (09) : 16 - 19
  • [23] A Survey: Typical Security Issues of Software-Defined Networking
    Liu, Yifan
    Zhao, Bo
    Zhao, Pengyuan
    Fan, Peiru
    Liu, Hui
    CHINA COMMUNICATIONS, 2019, 16 (07) : 13 - 31
  • [24] A Survey: Typical Security Issues of Software-Defined Networking
    Yifan Liu
    Bo Zhao
    Pengyuan Zhao
    Peiru Fan
    Hui Liu
    中国通信, 2019, 16 (07) : 13 - 31
  • [25] Software-Defined Networking
    Zhili Sun
    Jiandong Li
    Kun Yang
    ZTE Communications, 2014, 12 (02) : 1 - 2
  • [26] Software-Defined Networking for Unmanned Aerial Vehicular Networking and Security: A Survey
    Mccoy, James
    Rawat, Danda B.
    ELECTRONICS, 2019, 8 (12)
  • [27] An EC-Based Formalism for Policy Refinement in Software-Defined Networking
    Machado, Cristian Cleder
    Wickboldt, Juliano Araujo
    Granville, Lisandro Zambenedetti
    Schaeffer-Filho, Alberto
    2015 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2015, : 496 - 501
  • [28] A New Bandwidth Management Model using Software-Defined Networking Security Threats
    Nisar, Kashif
    Jimson, Emilia Rosa
    Hijazi, Mohd Hanafi bin Ahmad
    Ibrahim, Ag Asri Ag
    Park, Yong Jin
    Welch, Ian
    2019 IEEE 13TH INTERNATIONAL CONFERENCE ON APPLICATION OF INFORMATION AND COMMUNICATION TECHNOLOGIES (AICT 2019), 2019, : 189 - 191
  • [29] A Security Assessment Mechanism for Software-Defined Networking-Based Mobile Networks
    Luo, Shibo
    Dong, Mianxiong
    Ota, Kaoru
    Wu, Jun
    Li, Jianhua
    SENSORS, 2015, 15 (12): : 31843 - 31858
  • [30] SDSEP: A Network Security Education Platform based on Software-Defined Networking Technology
    Wu, Jun
    Wang, Shen
    Li, Jianhua
    Wu, Yang
    2016 8TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY IN MEDICINE AND EDUCATION (ITME), 2016, : 737 - 740