Security and Privacy Issues in Software-Defined Networking (SDN): A Systematic Literature Review

被引:16
作者
Farooq, Muhammad Shoaib [1 ]
Riaz, Shamyla [1 ]
Alvi, Atif [1 ]
机构
[1] Univ Management & Technol, Dept Comp Sci, Lahore 54770, Pakistan
关键词
SDN; software defined networking; application plane; control plane; data plane; SDN security; DDOS ATTACKS; SERVICE ATTACKS; PLANE SECURITY; MITIGATION; DEFENSE; IMPLEMENTATION; ACCELERATORS; MECHANISM; FRAMEWORK; IDS;
D O I
10.3390/electronics12143077
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined network (SDNs) have fundamentally changed network infrastructure by decoupling the data plane and the control plane. This architectural shift rejuvenates the network layer by granting the re-programmability and centralized management of networks which brings about exciting challenges. Although an SDN seems to be a secured network when compared to conventional networks, it is still vulnerable and faces rigorous deployment challenges. Moreover, the bifurcation of data and control planes also opens up new security problems. This systematic literature review (SLR) has formalized the problem by identifying the potential attack scenarios and highlighting the possible vulnerabilities. Eighty-six articles have been selected carefully to formulize the SLR. In this SLR, we have identified major security attacks on SDN planes, including the application plane, control plane, and data plane. Moreover, this research also identifies the approaches used by industry experts and researchers to develop security solutions for SDN planes. In this research, we have introduced an attack taxonomy and proposed a collaborative security model after comprehensively identifying security attacks on SDN planes. Lastly, research gaps, challenges, and future directions are discussed for the deployment of secure SDNs.
引用
收藏
页数:37
相关论文
共 184 条
[1]   Comparative Analysis of Control Plane Security of SDN and Conventional Networks [J].
Abdou, AbdelRahman ;
van Oorschot, Paul C. ;
Wan, Tao .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (04) :3542-3559
[2]  
Abdulkarem HS, 2020, 2020 IEEE 2ND GLOBAL POWER, ENERGY AND COMMUNICATION CONFERENCE (IEEE GPECOM2020), P322, DOI [10.1109/GPECOM49333.2020.9247850, 10.1109/gpecom49333.2020.9247850]
[3]  
Afek Y, 2017, IEEE INFOCOM SER
[4]   Fault Diagnosis Schemes for Low-Energy Block Cipher Midori Benchmarked on FPGA [J].
Aghaie, Anita ;
Kermani, Mehran Mozaffari ;
Azarderakhsh, Reza .
IEEE TRANSACTIONS ON VERY LARGE SCALE INTEGRATION (VLSI) SYSTEMS, 2017, 25 (04) :1528-1536
[5]  
Aghaie A, 2016, IEEE I C ELECT CIRC, P768, DOI 10.1109/ICECS.2016.7841315
[6]   Security in Software Defined Networks: A Survey [J].
Ahmad, Ijaz ;
Namal, Suneth ;
Ylianttila, Mika ;
Gurtov, Andrei .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04) :2317-2346
[7]   Network Threat Detection Using Machine/Deep Learning in SDN-Based Platforms: A Comprehensive Analysis of State-of-the-Art Solutions, Discussion, Challenges, and Future Research Direction [J].
Ahmed, Naveed ;
bin Ngadi, Asri ;
Sharif, Johan Mohamad ;
Hussain, Saddam ;
Uddin, Mueen ;
Rathore, Muhammad Siraj ;
Iqbal, Jawaid ;
Abdelhaq, Maha ;
Alsaqour, Raed ;
Ullah, Syed Sajid ;
Zuhra, Fatima Tul .
SENSORS, 2022, 22 (20)
[8]   Securing Software Defined Networks: Taxonomy, Requirements, and Open Issues [J].
Akhunzada, Adnan ;
Ahmed, Ejaz ;
Gani, Abdullah ;
Khan, Muhammad Khurram ;
Imran, Muhammad ;
Guizani, Sghaier .
IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (04) :36-44
[9]  
Akila J., 2016, INT ED RES J IERJ, V2
[10]  
Al-Shabibi A., 2014, P 3 WORKSH HOT TOP S, P25