Security Threats in the Data Plane of Software-Defined Networks

被引:38
|
作者
Gao, Shang [1 ]
Li, Zecheng [1 ]
Xiao, Bin [1 ]
Wei, Guiyi [2 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
[2] Zhejiang Gongshang Univ, Sch Comp Sci & Informat Engn, Hangzhou, Zhejiang, Peoples R China
来源
IEEE NETWORK | 2018年 / 32卷 / 04期
关键词
D O I
10.1109/MNET.2018.1700283
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN has enabled extensive network programmability and speedy network innovations by decoupling the control plane from the data plane. However, the separation of the two planes could also be a potential threat to the whole network. Previous approaches pointed out that attackers can launch various attacks from the data plane against SDN, such as DoS attacks, topology poisoning attacks, and side-channel attacks. To address the security issues, we present a comprehensive study of data plane attacks in SDN, and propose FlowKeeper, a common framework to build a robust data plane against different attacks. FlowKeeper enforces port control of the data plane and reduces the workload of the control plane by filtering out illegal packets. Experimental results show that FlowKeeper could be used to efficiently mitigate different kinds of attacks (i.e., DoS and topology poisoning attacks).
引用
收藏
页码:108 / 113
页数:6
相关论文
共 50 条
  • [1] Security in Software-Defined Networking: Threats and Countermeasures
    Shu, Zhaogang
    Wan, Jiafu
    Li, Di
    Lin, Jiaxiang
    Vasilakos, Athanasios V.
    Imran, Muhammad
    MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 764 - 776
  • [2] Security in Software-Defined Networking: Threats and Countermeasures
    Zhaogang Shu
    Jiafu Wan
    Di Li
    Jiaxiang Lin
    Athanasios V. Vasilakos
    Muhammad Imran
    Mobile Networks and Applications, 2016, 21 : 764 - 776
  • [3] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [4] Extended data plane architecture for in-network security services in software-defined networks
    Kim, Jinwoo
    Kim, Yeonkeun
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    Park, Taejune
    COMPUTERS & SECURITY, 2023, 124
  • [5] Security in Software-Defined Wireless Sensor Networks: Threats, Challenges and Potential Solutions
    Pritchard, Sean W.
    Hancke, Gerhard P.
    Abu-Mahfouz, Adnan M.
    2017 IEEE 15TH INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2017, : 168 - 173
  • [6] Software-Defined Mobile Networks Security
    Min Chen
    Yongfeng Qian
    Shiwen Mao
    Wan Tang
    Ximin Yang
    Mobile Networks and Applications, 2016, 21 : 729 - 743
  • [7] Security Evaluation in Software-Defined Networks
    Ivkic, Igor
    Thiede, Dominik
    Race, Nicholas
    Broadbent, Matthew
    Gouglidis, Antonios
    CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2022, CLOSER 2023, 2024, 1845 : 66 - 91
  • [8] Software-Defined Mobile Networks Security
    Chen, Min
    Qian, Yongfeng
    Mao, Shiwen
    Tang, Wan
    Yang, Ximin
    MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 729 - 743
  • [9] Fast Data Plane Testing for Software-Defined Networks With RuleChecker
    Zhang, Peng
    Zhang, Cheng
    Hu, Chengchen
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2019, 27 (01) : 173 - 186
  • [10] Troubleshooting Data Plane With Rule Verification in Software-Defined Networks
    Zhao, Yusu
    Zhang, Pengfei
    Wang, Yongkun
    Jin, Yaohui
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2018, 15 (01): : 232 - 244