On the Design and Implementation of a Security Architecture for Software Defined Networks

被引:0
|
作者
Karmakar, Kallol Krishna [1 ]
Varadharajan, Vijay [1 ]
Tupakula, Udaya [1 ]
机构
[1] Macquarie Univ, Fac Sci, Adv Cyber Secur Res Ctr, Sydney, NSW, Australia
关键词
Software Defined Networking (SDN) Security; OpenFlow; ACL; Source Spoofing; Policy Control;
D O I
10.1109/HPCC-SmartCity-DSS.2016.138
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose techniques for securing Software Defined Networks(SDN). We describe the design of a security architecture that makes use of security applications on top of the SDN Controller to specify fine granular security policies based on domain wide knowledge of the domain and Security Agents to enforce these policies in the switches in the data plane. We have extended the Open Flow protocol to enable communication of the security policies between the security applications in the Controller to the agents in the switches. We have implemented the security architecture using POX Controller and demonstrated the operation of our architecture in a range of scenarios such as enforcing specific security policies for different traffic with different services, counteracting attacks such as Heartbleed and Shellshock as well as spoofing attacks, and protecting Content Management Systems(CMS) from data confidentiality attacks.
引用
收藏
页码:671 / 678
页数:8
相关论文
共 50 条
  • [1] On the Design and Implementation of a Security Architecture for End to End Services in Software Defined Networks
    Karmakar, Kallol Krishna
    Varadharajan, Vijay
    Tupakula, Udaya
    2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 519 - 522
  • [2] Design and Implementation of a Security Control Architecture for Software-Defined Networking
    Liu, Tie-jun
    Lin, Zhao-wen
    Xu, Jie
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND COMMUNICATION TECHNOLOGY (CNCT 2016), 2016, 54 : 779 - 785
  • [3] Design and Implementation of a Software-Defined Mobility Architecture for IP Networks
    You Wang
    Jun Bi
    Keyao Zhang
    Mobile Networks and Applications, 2015, 20 : 40 - 52
  • [4] Design and Implementation of a Software-Defined Mobility Architecture for IP Networks
    Wang, You
    Bi, Jun
    Zhang, Keyao
    MOBILE NETWORKS & APPLICATIONS, 2015, 20 (01): : 40 - 52
  • [5] WSN Architecture Design Based on Software Defined Networks
    He, Tian
    Hai, Zhao
    Shao Shi-liang
    PROCEEDINGS OF THE 2017 2ND INTERNATIONAL CONFERENCE ON AUTOMATIC CONTROL AND INFORMATION ENGINEERING (ICACIE 2017), 2017, 119 : 154 - 157
  • [6] Demo: The Design and Implementation of Intelligent Software Defined Security Framework
    Zhang, Shasha
    Song, Shuyu
    Yang, Fan
    Li, Rongpeng
    Zhao, Zhifeng
    Zhang, Honggang
    MOBICOM'19: PROCEEDINGS OF THE 25TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING, 2019,
  • [7] Programmable Software-Defined Testbed for Visible Light UAV Networks: Architecture Design and Implementation
    Zhang, Yue
    Cen, Nan
    2023 IEEE 20TH CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2023,
  • [8] A Policy-Based Security Architecture for Software-Defined Networks
    Varadharajan, Vijay
    Karmakar, Kallol
    Tupakula, Uday
    Hitchens, Michael
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (04) : 897 - 912
  • [9] On the Design of Efficient Hierarchic Architecture for Software Defined Vehicular Networks
    Adnan, Muhammad
    Iqbal, Jawaid
    Waheed, Abdul
    Amin, Noor Ul
    Zareei, Mahdi
    Goudarzi, Shidrokh
    Umer, Asif
    SENSORS, 2021, 21 (04) : 1 - 18
  • [10] Design and Implementation of Security for HIMALIS Architecture of Future Networks
    Kafle, Ved P.
    Li, Ruidong
    Inoue, Daisuke
    Harai, Hiroaki
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2013, E96D (02): : 226 - 237