OpenSec: Policy-Based Security Using Software-Defined Networking

被引:58
|
作者
Lara, Adrian [1 ]
Ramamurthy, Byrav [1 ]
机构
[1] Univ Nebraska, Dept Comp Sci & Engn, Lincoln, NE 68588 USA
基金
美国国家科学基金会;
关键词
Software-defined networking; OpenFlow; network security; policy-based network management; policy specification; MANAGEMENT;
D O I
10.1109/TNSM.2016.2517407
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the popularity of software-defined networks (SDN) and OpenFlow increases, policy-driven network management has received more attention. Manual configuration of multiple devices is being replaced by an automated approach where a software-based, network-aware controller handles the configuration of all network devices. Software applications running on top of the network controller provide an abstraction of the topology and facilitate the task of operating the network. We propose OpenSec, an OpenFlow-based security framework that allows a network security operator to create and implement security policies written in human-readable language. Using OpenSec, the user can describe a flow in terms of OpenFlow matching fields, define which security services must be applied to that flow (deep packet inspection, intrusion detection, spam detection, etc.) and specify security levels that define how OpenSec reacts if malicious traffic is detected. In this paper, we first provide a more detailed explanation of how OpenSec converts security policies into a series of OpenFlow messages needed to implement such a policy. Second, we describe how the framework automatically reacts to security alerts as specified by the policies. Third, we perform additional experiments on the GENI testbed to evaluate the scalability of the proposed framework using existing datasets of campus networks. Our results show that up to 95% of attacks in an existing data set can be detected and 99% of malicious source nodes can be blocked automatically. Furthermore, we show that our policy specification language is simpler while offering fast translation times compared to existing solutions.
引用
收藏
页码:30 / 42
页数:13
相关论文
共 50 条
  • [31] Content-Based Security and Protected Core Networking with Software-Defined Networks
    Wrona, Konrad
    Oudkerk, Sander
    Szwaczyk, Sebastian
    Amanowicz, Marek
    IEEE COMMUNICATIONS MAGAZINE, 2016, 54 (10) : 138 - 144
  • [32] A Security Mechanism for Software-Defined Networking Based Communications in Vehicle-to-Grid
    Zhang, Shanghua
    Li, Qiang
    Wu, Jun
    Li, Jianhua
    Li, Gaolei
    2016 THE 4TH IEEE INTERNATIONAL CONFERENCE ON SMART ENERGY GRID ENGINEERING (SEGE), 2016, : 386 - 391
  • [33] Towards Blockchain-Based Software-Defined Networking: Security Challenges and Solutions
    Li, Wenjuan
    Meng, Weizhi
    Liu, Zhigiang
    Au, Man-Ho
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2020, E103D (02) : 196 - 203
  • [34] Construction of switch information security protection system based on software-defined networking
    Huang, Xueda
    Zheng, Kuanlei
    Chen, Sisi
    He, Zhaoren
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2024, 35 (09):
  • [35] Design and Implementation of a Security Control Architecture for Software-Defined Networking
    Liu, Tie-jun
    Lin, Zhao-wen
    Xu, Jie
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND COMMUNICATION TECHNOLOGY (CNCT 2016), 2016, 54 : 779 - 785
  • [36] Advances in security analysis of software-defined networking flow rules
    Xiong W.
    Mao J.
    Liu Z.
    Liu W.
    Liu J.
    Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University, 2023, 50 (06): : 172 - 194
  • [37] Blessing or Curse? Revisiting Security Aspects of Software-Defined Networking
    Schehlmann, Lisa
    Abt, Sebastian
    Baier, Harald
    2014 10TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2014, : 382 - 387
  • [38] A security and trust framework for virtualized networks and software-defined networking
    Yan, Zheng
    Zhang, Peng
    Vasilakos, Athanasios V.
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (16) : 3059 - 3069
  • [39] Enabling Practical Software-defined Networking Security Applications with OFX
    Sonchack, John
    Aviv, Adam J.
    Keller, Eric
    Smith, Jonathan M.
    23RD ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2016), 2016,
  • [40] How to use Software-Defined Networking to Improve Security - a Survey
    Proenca, Jorge
    Cruz, Tiago
    Monteiro, Edmundo
    Simoes, Paulo
    PROCEEDINGS OF THE 14TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS-2015), 2015, : 220 - 228