Security Threats in the Data Plane of Software-Defined Networks

被引:38
|
作者
Gao, Shang [1 ]
Li, Zecheng [1 ]
Xiao, Bin [1 ]
Wei, Guiyi [2 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
[2] Zhejiang Gongshang Univ, Sch Comp Sci & Informat Engn, Hangzhou, Zhejiang, Peoples R China
来源
IEEE NETWORK | 2018年 / 32卷 / 04期
关键词
D O I
10.1109/MNET.2018.1700283
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN has enabled extensive network programmability and speedy network innovations by decoupling the control plane from the data plane. However, the separation of the two planes could also be a potential threat to the whole network. Previous approaches pointed out that attackers can launch various attacks from the data plane against SDN, such as DoS attacks, topology poisoning attacks, and side-channel attacks. To address the security issues, we present a comprehensive study of data plane attacks in SDN, and propose FlowKeeper, a common framework to build a robust data plane against different attacks. FlowKeeper enforces port control of the data plane and reduces the workload of the control plane by filtering out illegal packets. Experimental results show that FlowKeeper could be used to efficiently mitigate different kinds of attacks (i.e., DoS and topology poisoning attacks).
引用
收藏
页码:108 / 113
页数:6
相关论文
共 50 条
  • [21] A comprehensive security assessment framework for software-defined networks
    Lee, Seungsoo
    Kim, Jinwoo
    Woo, Seungwon
    Yoon, Changhoon
    Scott-Hayward, Sandra
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    COMPUTERS & SECURITY, 2020, 91
  • [22] OpenFlow Communications and TLS Security in Software-Defined Networks
    Agborubere, Belema
    Sanchez-Velazquez, Erika
    2017 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2017, : 560 - 566
  • [23] DELTA: A Security Assessment Framework for Software-Defined Networks
    Lee, Seungsoo
    Yoon, Changhoon
    Lee, Chanhee
    Shin, Seungwon
    Yegneswaran, Vinod
    Porras, Phillip
    24TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2017), 2017,
  • [24] Deep learning for the security of software-defined networks: a review
    Roya Taheri
    Habib Ahmed
    Engin Arslan
    Cluster Computing, 2023, 26 : 3089 - 3112
  • [25] SPHINX: Detecting Security Attacks in Software-Defined Networks
    Dhawan, Mohan
    Poddar, Rishabh
    Mahajan, Kshiteej
    Mann, Vijay
    22ND ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2015), 2015,
  • [26] Deep learning for the security of software-defined networks: a review
    Taheri, Roya
    Ahmed, Habib
    Arslan, Engin
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2023, 26 (05): : 3089 - 3112
  • [27] Security and performance of software-defined networks and functions virtualization
    Hausheer, David
    Hohlfeld, Oliver
    Schmid, Stefan
    Gu, Guofei
    COMPUTER NETWORKS, 2018, 138 : 15 - 17
  • [28] ANCHOR: Logically Centralized Security for Software-Defined Networks
    Kreutz, Diego
    Yu, Jiangshan
    Ramos, Fernando M. V.
    Esteves-Verissimo, Paulo
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2019, 22 (02)
  • [30] Software-Defined Optical Data Centre Networks
    Peng Shuping
    Guo Bingli
    Shu Yi
    Zervas, George
    Nejabati, Reza
    Simeonidou, Dimitra
    CHINA COMMUNICATIONS, 2015, 12 (08) : 1 - 9