Towards adoption of secure communication protocol in Software Defined Networks

被引:1
作者
Kancherla, Gayatri Priyadarsini [1 ]
Kulkarni, Sameer G. [1 ]
机构
[1] Indian Inst Technol Gandhinagar, Gandhinagar, India
来源
2023 15TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS, COMSNETS | 2023年
关键词
Software Defined Networks(SDN); Security; OpenFlow; TLSv1.3;
D O I
10.1109/COMSNETS56262.2023.10041364
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) decouples the forwarding data plane from the network control plane to provide centralized control and programmability of the data plane elements like switches and routers. Traditionally, this communication between control plane and the data plane (southbound communication) for e.g., using OpenFlow were based on the nonsecure protocol like transmission control protocol (TCP), which over-the-years resulted in several security incidents. In order to facilitate secure data communication, the adoption of transport layer security (TLS) has become unavoidable. To this extent, we first present the key qualitative aspects and suitability of using TLS 1.2 and the newer TLS 1.3 for southbound communication. Further, we present extensive quantitative evaluation on Mininet emulator testbed to assess the performance impact of using the TLS 1.2 and TLS 1.3 (for most widely used cipher suites) over TCP to secure the controller-switch communication. Our work shows that the adoption of secure communication channel TLS incurs significant overheads (similar to 2 - 6x) when compared to baseline TCP (unsecure channel), while TLS 1.3 adds marginal overheads in terms of latency and throughput (similar to 5%) in comparison to TLS 1.2. Also, we observed that the memory and processing (computational cost) overheads with TLS 1.2 and TLS 1.3 to be negligible, even when supporting a large number of flows. Further, we also discuss the potential adoption of QUIC protocol as an alternative to provide high performance secure communication for the southbound interface.
引用
收藏
页数:8
相关论文
共 41 条
[1]   OpenFlow Communications and TLS Security in Software-Defined Networks [J].
Agborubere, Belema ;
Sanchez-Velazquez, Erika .
2017 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2017, :560-566
[2]  
[Anonymous], 2003, PACKET SNIFFING LAYE
[3]  
[Anonymous], About us
[4]  
[Anonymous], 2014, Openflow switch specification 1.5.0
[5]  
Apache, Ab-Apache HTTP Server Benchmarking Tool v2.3
[6]  
Avallone S, 2004, INT CONF QUANT EVAL, P316
[7]  
Baidya Sonali Sen, 2020, J. Commun., V15, P596
[8]  
Berde P., 2014, P 3 WORKSH HOT TOP S, P1
[9]  
Bishop Mike, 2022, 9114 RFC
[10]  
Cao JH, 2019, PROCEEDINGS OF THE 28TH USENIX SECURITY SYMPOSIUM, P19