Security Threats in the Data Plane of Software-Defined Networks

被引:38
|
作者
Gao, Shang [1 ]
Li, Zecheng [1 ]
Xiao, Bin [1 ]
Wei, Guiyi [2 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
[2] Zhejiang Gongshang Univ, Sch Comp Sci & Informat Engn, Hangzhou, Zhejiang, Peoples R China
来源
IEEE NETWORK | 2018年 / 32卷 / 04期
关键词
D O I
10.1109/MNET.2018.1700283
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN has enabled extensive network programmability and speedy network innovations by decoupling the control plane from the data plane. However, the separation of the two planes could also be a potential threat to the whole network. Previous approaches pointed out that attackers can launch various attacks from the data plane against SDN, such as DoS attacks, topology poisoning attacks, and side-channel attacks. To address the security issues, we present a comprehensive study of data plane attacks in SDN, and propose FlowKeeper, a common framework to build a robust data plane against different attacks. FlowKeeper enforces port control of the data plane and reduces the workload of the control plane by filtering out illegal packets. Experimental results show that FlowKeeper could be used to efficiently mitigate different kinds of attacks (i.e., DoS and topology poisoning attacks).
引用
收藏
页码:108 / 113
页数:6
相关论文
共 50 条
  • [41] Robust hierarchical control plane for Transport Software-Defined Networks
    Lourenco, Rafael B. R.
    Savas, S. Sedef
    Tornatore, Massimo
    Mukherjee, Biswanath
    OPTICAL SWITCHING AND NETWORKING, 2018, 30 : 10 - 22
  • [42] Dynamic Management of Control Plane Performance in Software-Defined Networks
    Gorkemli, Burak
    Parlakisik, A. Murat
    Civanlar, Seyhan
    Ulas, Aydin
    Tekalp, A. Murat
    2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 68 - 72
  • [43] On High Availability Distributed Control Plane for Software-Defined Networks
    Pashkov, V.
    Smeliansky, R.
    2018 INTERNATIONAL SCIENTIFIC AND TECHNICAL CONFERENCE MODERN COMPUTER NETWORK TECHNOLOGIES (MONETEC 2018), 2018,
  • [44] Modelling cyber security for software-defined networks those grow strong when exposed to threats: Analysis and propositions
    Ahmed U.
    Raza I.
    Hussain S.A.
    Ali A.
    Iqbal M.
    Wang X.
    Journal of Reliable Intelligent Environments, 2015, 1 (2-4) : 123 - 146
  • [45] Opportunities and Challenges of Software-Defined Mobile Networks in Network Security
    Liyanage, Madhusanka
    Abro, Ahmed Bux
    Ylianttila, Mika
    Gurtov, Andrei
    IEEE SECURITY & PRIVACY, 2016, 14 (04) : 34 - 44
  • [46] A survey on software-defined vehicular networks (SDVNs): a security perspective
    Kumar, Rohit
    Agrawal, Neha
    JOURNAL OF SUPERCOMPUTING, 2023, 79 (08): : 8368 - 8400
  • [47] Automated Verification of Security Chains in Software-Defined Networks with Synaptic
    Schnepf, Nicolas
    Badonnel, Remi
    Lahmadi, Abdelkader
    Merz, Stephan
    2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [48] A security and trust framework for virtualized networks and software-defined networking
    Yan, Zheng
    Zhang, Peng
    Vasilakos, Athanasios V.
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (16) : 3059 - 3069
  • [49] Collaborative Security Attack Detection in Software-Defined Vehicular Networks
    Kim, Myeongsu
    Jang, Insun
    Choo, Sukjin
    Koo, Jungwoo
    Pack, Sangheon
    2017 19TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS 2017): MANAGING A WORLD OF THINGS, 2017, : 19 - 24
  • [50] A Collaborative Security Framework for Software-Defined Wireless Sensor Networks
    Miranda, Christian
    Kaddoum, Georges
    Bou-Harb, Elias
    Garg, Sahil
    Kaur, Kuljeet
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 2602 - 2615