OpenSec: Policy-Based Security Using Software-Defined Networking

被引:58
|
作者
Lara, Adrian [1 ]
Ramamurthy, Byrav [1 ]
机构
[1] Univ Nebraska, Dept Comp Sci & Engn, Lincoln, NE 68588 USA
基金
美国国家科学基金会;
关键词
Software-defined networking; OpenFlow; network security; policy-based network management; policy specification; MANAGEMENT;
D O I
10.1109/TNSM.2016.2517407
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the popularity of software-defined networks (SDN) and OpenFlow increases, policy-driven network management has received more attention. Manual configuration of multiple devices is being replaced by an automated approach where a software-based, network-aware controller handles the configuration of all network devices. Software applications running on top of the network controller provide an abstraction of the topology and facilitate the task of operating the network. We propose OpenSec, an OpenFlow-based security framework that allows a network security operator to create and implement security policies written in human-readable language. Using OpenSec, the user can describe a flow in terms of OpenFlow matching fields, define which security services must be applied to that flow (deep packet inspection, intrusion detection, spam detection, etc.) and specify security levels that define how OpenSec reacts if malicious traffic is detected. In this paper, we first provide a more detailed explanation of how OpenSec converts security policies into a series of OpenFlow messages needed to implement such a policy. Second, we describe how the framework automatically reacts to security alerts as specified by the policies. Third, we perform additional experiments on the GENI testbed to evaluate the scalability of the proposed framework using existing datasets of campus networks. Our results show that up to 95% of attacks in an existing data set can be detected and 99% of malicious source nodes can be blocked automatically. Furthermore, we show that our policy specification language is simpler while offering fast translation times compared to existing solutions.
引用
收藏
页码:30 / 42
页数:13
相关论文
共 50 条
  • [41] Software-Defined Networking for Improving Security in Smart Grid Systems
    Demirci, Sedef
    Sagiroglu, Seref
    2018 7TH INTERNATIONAL CONFERENCE ON RENEWABLE ENERGY RESEARCH AND APPLICATIONS (ICRERA), 2018, : 1021 - 1026
  • [42] A Survey on Software-Defined Networking
    Xia, Wenfeng
    Wen, Yonggang
    Foh, Chuan Heng
    Niyato, Dusit
    Xie, Haiyong
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (01): : 27 - 51
  • [43] Software-Defined Networking: A survey
    Farhady, Hamid
    Lee, HyunYong
    Nakao, Akihiro
    COMPUTER NETWORKS, 2015, 81 : 79 - 95
  • [44] On Scalability of Software-Defined Networking
    Yeganeh, Soheil Hassas
    Tootoonchian, Amin
    Ganjali, Yashar
    IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (02) : 136 - 141
  • [45] Efficient routing for middlebox policy enforcement in software-defined networking
    Li, Xin
    Wu, Haotian
    Gruenbacher, Don
    Scoglio, Caterina
    Anjali, Tricha
    COMPUTER NETWORKS, 2016, 110 : 243 - 252
  • [46] Software-Defined Networking Security System Using Machine Learning Algorithms and Entropy-Based Features
    Shankaraiah
    Shashank, S.
    SUSTAINABLE COMMUNICATION NETWORKS AND APPLICATION, ICSCN 2021, 2022, 93 : 507 - 520
  • [47] Software-Defined Networking Application with Deep Deterministic Policy Gradient
    Witanto, Joseph Nathanael
    Lim, Hyotaek
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON COMPUTER MODELING AND SIMULATION (ICCMS 2019) AND 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND APPLICATIONS (ICICA 2019), 2019, : 176 - 179
  • [48] DAI: Dynamic ACL Policy Implementation for Software-Defined Networking
    Ali, Mujahid
    Shah, Nadir
    Khattak, Muazzam A. Khan
    2020 IEEE 17TH INTERNATIONAL CONFERENCE ON SMART COMMUNITIES: IMPROVING QUALITY OF LIFE USING ICT, IOT AND AI (IEEEHONET 2020), 2020, : 138 - 142
  • [49] Network virtualization by using software-defined networking controller based Docker
    Liu Xingtao
    Guo Yantao
    Wu Wei
    Zhou Sanyou
    Li Jiliang
    2016 IEEE INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC), 2016, : 1112 - 1115
  • [50] A Policy-based Interaction Protocol between Software Defined Security Controller and Virtual Security Functions
    Farahmandian, Sara
    Hoang, Doan B.
    2020 FOURTH CYBER SECURITY IN NETWORKING CONFERENCE (CSNET), 2020,