Security and Privacy Issues in Software-Defined Networking (SDN): A Systematic Literature Review

被引:16
作者
Farooq, Muhammad Shoaib [1 ]
Riaz, Shamyla [1 ]
Alvi, Atif [1 ]
机构
[1] Univ Management & Technol, Dept Comp Sci, Lahore 54770, Pakistan
关键词
SDN; software defined networking; application plane; control plane; data plane; SDN security; DDOS ATTACKS; SERVICE ATTACKS; PLANE SECURITY; MITIGATION; DEFENSE; IMPLEMENTATION; ACCELERATORS; MECHANISM; FRAMEWORK; IDS;
D O I
10.3390/electronics12143077
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined network (SDNs) have fundamentally changed network infrastructure by decoupling the data plane and the control plane. This architectural shift rejuvenates the network layer by granting the re-programmability and centralized management of networks which brings about exciting challenges. Although an SDN seems to be a secured network when compared to conventional networks, it is still vulnerable and faces rigorous deployment challenges. Moreover, the bifurcation of data and control planes also opens up new security problems. This systematic literature review (SLR) has formalized the problem by identifying the potential attack scenarios and highlighting the possible vulnerabilities. Eighty-six articles have been selected carefully to formulize the SLR. In this SLR, we have identified major security attacks on SDN planes, including the application plane, control plane, and data plane. Moreover, this research also identifies the approaches used by industry experts and researchers to develop security solutions for SDN planes. In this research, we have introduced an attack taxonomy and proposed a collaborative security model after comprehensively identifying security attacks on SDN planes. Lastly, research gaps, challenges, and future directions are discussed for the deployment of secure SDNs.
引用
收藏
页数:37
相关论文
共 184 条
[21]  
Antikainen Markku, 2014, Secure IT Systems 19th Nordic Conference, NordSec 2014. Proceedings: LNCS 8788, P229, DOI 10.1007/978-3-319-11599-3_14
[22]   LION IDS: A meta-heuristics approach to detect DDoS attacks against Software-Defined Networks [J].
Arivudainambi, D. ;
Kumar, Varun K. A. ;
Chakkaravarthy, S. Sibi .
NEURAL COMPUTING & APPLICATIONS, 2019, 31 (05) :1491-1501
[23]   Adaptive Machine Learning Based Distributed Denial-of-Services Attacks Detection and Mitigation System for SDN-Enabled IoT [J].
Aslam, Muhammad ;
Ye, Dengpan ;
Tariq, Aqil ;
Asad, Muhammad ;
Hanif, Muhammad ;
Ndzi, David ;
Chelloug, Samia Allaoua ;
Abd Elaziz, Mohamed ;
Al-Qaness, Mohammed A. A. ;
Jilani, Syeda Fizzah .
SENSORS, 2022, 22 (07)
[24]   Robust Self-Protection Against Application-Layer (D)DoS Attacks in SDN Environment [J].
Benzaid, Chafika ;
Boukhalfa, Mohammed ;
Taleb, Tarik .
2020 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2020,
[25]   Devolving IEEE 802.1X authentication capability to data plane in software-defined networking (SDN) architecture [J].
Benzekki, Kamal ;
El Fergougui, Abdeslam ;
El Alaoui, Abdelbaki El Belrhiti .
SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (17) :4369-4377
[26]   Cryptographic Accelerators for Digital Signature Based on Ed25519 [J].
Bisheh-Niasar, Mojtaba ;
Azarderakhsh, Reza ;
Mozaffari-Kermani, Mehran .
IEEE TRANSACTIONS ON VERY LARGE SCALE INTEGRATION (VLSI) SYSTEMS, 2021, 29 (07) :1297-1305
[27]  
Boite J, 2017, 2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT)
[28]  
Braga R, 2010, C LOCAL COMPUT NETW, P408, DOI 10.1109/LCN.2010.5735752
[29]  
Brooks M., 2015, Proceedings of the 4th Annual ACM Conference on Research in Information Technology - RIIT'15, P45, DOI [10.1145/2808062, DOI 10.1145/2808062]
[30]  
Cai Z., 2010, Maestro: A System for Scalable Open- Flow Control. Technical report