On the Design and Implementation of a Security Architecture for Software Defined Networks

被引:0
|
作者
Karmakar, Kallol Krishna [1 ]
Varadharajan, Vijay [1 ]
Tupakula, Udaya [1 ]
机构
[1] Macquarie Univ, Fac Sci, Adv Cyber Secur Res Ctr, Sydney, NSW, Australia
关键词
Software Defined Networking (SDN) Security; OpenFlow; ACL; Source Spoofing; Policy Control;
D O I
10.1109/HPCC-SmartCity-DSS.2016.138
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose techniques for securing Software Defined Networks(SDN). We describe the design of a security architecture that makes use of security applications on top of the SDN Controller to specify fine granular security policies based on domain wide knowledge of the domain and Security Agents to enforce these policies in the switches in the data plane. We have extended the Open Flow protocol to enable communication of the security policies between the security applications in the Controller to the agents in the switches. We have implemented the security architecture using POX Controller and demonstrated the operation of our architecture in a range of scenarios such as enforcing specific security policies for different traffic with different services, counteracting attacks such as Heartbleed and Shellshock as well as spoofing attacks, and protecting Content Management Systems(CMS) from data confidentiality attacks.
引用
收藏
页码:671 / 678
页数:8
相关论文
共 50 条
  • [31] Software-Defined Mobile Networks Security
    Min Chen
    Yongfeng Qian
    Shiwen Mao
    Wan Tang
    Ximin Yang
    Mobile Networks and Applications, 2016, 21 : 729 - 743
  • [32] Security Evaluation in Software-Defined Networks
    Ivkic, Igor
    Thiede, Dominik
    Race, Nicholas
    Broadbent, Matthew
    Gouglidis, Antonios
    CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2022, CLOSER 2023, 2024, 1845 : 66 - 91
  • [33] SDSA: A Framework of a Software-Defined Security Architecture
    Liu Yanbing
    Lu Xingyu
    Jian Yi
    Xiao Yunpeng
    CHINA COMMUNICATIONS, 2016, 13 (02) : 178 - 188
  • [34] An Intelligent Honeynet Architecture Based on Software Defined Security
    Meng, Xiangjun
    Zhao, Zhifeng
    Li, Rongpeng
    Zhang, Honggang
    2017 9TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS AND SIGNAL PROCESSING (WCSP), 2017,
  • [35] Special Session: Emerging Architecture Design, Control, and Security Challenges in Software Defined Vehicles
    El-Fatyany, Aya
    Wang, Xiaohang
    Duggirala, Parasara Sridhar
    Chakraborty, Samarjit
    Pasricha, Sudeep
    Singh, Amit Kumar
    2024 INTERNATIONAL CONFERENCE ON HARDWARE/SOFTWARE CODESIGN AND SYSTEM SYNTHESIS, CODES+ISSS 2024, 2024, : 31 - 40
  • [36] A Software-Defined Networking Security Controller Architecture
    Shang, Fengjun
    Fu, Qiang
    PROCEEDINGS OF THE 2016 4TH INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND COMPUTING TECHNOLOGY, 2016, 60 : 229 - 234
  • [37] A WebRTC Architecture Assisted by Software Defined Networks
    Unver, Alp
    Kheibari, Bita
    Sayit, Mtige
    2020 28TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2020,
  • [38] Architecture of Segmentation Service of Software Defined Networks
    Perepelkin, Dmitry
    Tsyganov, Ilya
    Ivanchikova, Maria
    2020 9TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO), 2020, : 599 - 603
  • [39] Towards the Design of Efficient and Secure Architecture for Software-Defined Vehicular Networks
    Adnan, Muhammad
    Iqbal, Jawaid
    Waheed, Abdul
    Amin, Noor Ul
    Zareei, Mahdi
    Umer, Asif
    Mohamed, Ehab Mahmoud
    SENSORS, 2021, 21 (11)
  • [40] Design and implementation of MobiSEC: A complete security architecture for wireless mesh networks
    Martignon, Fabio
    Paris, Stefano
    Capone, Antonio
    COMPUTER NETWORKS, 2009, 53 (12) : 2192 - 2207