Security Evaluation in Software-Defined Networks

被引:0
|
作者
Ivkic, Igor [1 ,2 ]
Thiede, Dominik [2 ]
Race, Nicholas [1 ]
Broadbent, Matthew [3 ]
Gouglidis, Antonios [1 ]
机构
[1] Univ Lancaster, Lancaster, England
[2] Univ Appl Sci Burgenland, Eisenstadt, Austria
[3] Edinburgh Napier Univ, Edinburgh, Midlothian, Scotland
关键词
Software-defined networks; Security evaluation framework; Threat analysis; Risk assessment; Attack modelling; Threat mitigation;
D O I
10.1007/978-3-031-68165-3_4
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cloud computing has grown in importance in recent years which has led to a significant increase in Data Centre (DC) network requirements. A major driver of this change is virtualisation, which allows computing resources to be deployed on a large scale. However, traditional DCs, with their network topology and proliferation of network endpoints, are struggling to meet the flexible, centrally managed requirements of cloud computing applications. Software-Defined Networks (SDN) promise to offer a solution to these growing networking requirements by separating control functions from data routing. This shift adds more flexibility to networks but also introduces new security issues. This article presents a framework for evaluating security of SDN architectures. In addition, through an experimental study, we demonstrate how this framework can identify the threats and vulnerabilities, calculate their risks and severity, and provide the necessary measures to mitigate them. The proposed framework helps administrators to evaluate SDN security, address identified threats and meet network security requirements.
引用
收藏
页码:66 / 91
页数:26
相关论文
共 50 条
  • [1] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [2] Software-Defined Mobile Networks Security
    Min Chen
    Yongfeng Qian
    Shiwen Mao
    Wan Tang
    Ximin Yang
    Mobile Networks and Applications, 2016, 21 : 729 - 743
  • [3] Software-Defined Mobile Networks Security
    Chen, Min
    Qian, Yongfeng
    Mao, Shiwen
    Tang, Wan
    Yang, Ximin
    MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 729 - 743
  • [4] Improving the Routing Security in Software-Defined Networks
    Ai, Jianjian
    Guo, Zehua
    Chen, Hongchang
    Cheng, Guozhen
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (05) : 838 - 841
  • [5] Semantic Security Tools in Software-Defined Networks
    Antoshina, E. Ju.
    Chalyy, D. Ju.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2018, 52 (07) : 605 - 607
  • [6] Hybrid Testbed for Security Research in Software-Defined Networks
    Windisch, Fritz
    Abedi, Kamyar
    Doan, Tung
    Strufe, Thorsten
    Nguyen, Giang T.
    2023 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS, NFV-SDN, 2023, : 147 - 152
  • [7] Security Threats in the Data Plane of Software-Defined Networks
    Gao, Shang
    Li, Zecheng
    Xiao, Bin
    Wei, Guiyi
    IEEE NETWORK, 2018, 32 (04): : 108 - 113
  • [8] Automated Factorization of Security Chains in Software-Defined Networks
    Schnepf, Nicolas
    Badonnel, Remi
    Lahmadi, Abdelkader
    Merz, Stephan
    2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019, : 374 - 380
  • [9] A comprehensive security assessment framework for software-defined networks
    Lee, Seungsoo
    Kim, Jinwoo
    Woo, Seungwon
    Yoon, Changhoon
    Scott-Hayward, Sandra
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    COMPUTERS & SECURITY, 2020, 91
  • [10] OpenFlow Communications and TLS Security in Software-Defined Networks
    Agborubere, Belema
    Sanchez-Velazquez, Erika
    2017 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2017, : 560 - 566