Security and Privacy Issues in Software-Defined Networking (SDN): A Systematic Literature Review

被引:16
作者
Farooq, Muhammad Shoaib [1 ]
Riaz, Shamyla [1 ]
Alvi, Atif [1 ]
机构
[1] Univ Management & Technol, Dept Comp Sci, Lahore 54770, Pakistan
关键词
SDN; software defined networking; application plane; control plane; data plane; SDN security; DDOS ATTACKS; SERVICE ATTACKS; PLANE SECURITY; MITIGATION; DEFENSE; IMPLEMENTATION; ACCELERATORS; MECHANISM; FRAMEWORK; IDS;
D O I
10.3390/electronics12143077
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined network (SDNs) have fundamentally changed network infrastructure by decoupling the data plane and the control plane. This architectural shift rejuvenates the network layer by granting the re-programmability and centralized management of networks which brings about exciting challenges. Although an SDN seems to be a secured network when compared to conventional networks, it is still vulnerable and faces rigorous deployment challenges. Moreover, the bifurcation of data and control planes also opens up new security problems. This systematic literature review (SLR) has formalized the problem by identifying the potential attack scenarios and highlighting the possible vulnerabilities. Eighty-six articles have been selected carefully to formulize the SLR. In this SLR, we have identified major security attacks on SDN planes, including the application plane, control plane, and data plane. Moreover, this research also identifies the approaches used by industry experts and researchers to develop security solutions for SDN planes. In this research, we have introduced an attack taxonomy and proposed a collaborative security model after comprehensively identifying security attacks on SDN planes. Lastly, research gaps, challenges, and future directions are discussed for the deployment of secure SDNs.
引用
收藏
页数:37
相关论文
共 184 条
[31]   Resilient backup controller placement in distributed SDN under critical targeted attacks [J].
Calle, Eusebi ;
Martinez, David ;
Mycek, Mariusz ;
Pioro, Michal .
INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2021, 33
[32]  
Canto AC, 2023, Arxiv, DOI arXiv:2305.13544
[33]   Enhancing security of SDN focusing on control plane and data plane [J].
Celesova, Barbora ;
Val'ko, Jozef ;
Grezo, Rudolf ;
Helebrandt, Pavol .
2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,
[34]  
Chen KY, 2016, IEEE CONF COMM NETW, P28, DOI 10.1109/CNS.2016.7860467
[35]   Behavior Anomaly Detection in SDN Control Plane: A Case Study of Topology Discovery Attacks [J].
Chou, Li-Der ;
Liu, Chien-Chang ;
Lai, Meng-Sheng ;
Chiu, Kai-Cheng ;
Tu, Hsuan-Hao ;
Su, Sen ;
Lai, Chun-Lin ;
Yen, Chia-Kuan ;
Tsai, Wei-Hsiang .
WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2020, 2020
[36]   Lightweight solutions to counter DDoS attacks in software defined networking [J].
Conti, Mauro ;
Lal, Chhagan ;
Mohammadi, Reza ;
Rawat, Umashankar .
WIRELESS NETWORKS, 2019, 25 (05) :2751-2768
[37]   SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks [J].
Cui, Yunhe ;
Yan, Lianshan ;
Li, Saifei ;
Xing, Huanlai ;
Pan, Wei ;
Zhu, Jian ;
Zheng, Xiaoyang .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 68 :65-79
[38]   A Survey on Fault Management in Software-Defined Networks [J].
da Rocha Fonseca, Paulo Cesar ;
Mota, Edjard Souza .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (04) :2284-2321
[39]   NGS: Mitigating DDoS Attacks using SDN-based Network Gate Shield [J].
Dalati, Mohamad Suhel ;
Meng, Weizhi ;
Chiu, Wei-Yang .
2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,
[40]  
David E.S., 2003, P 11 IEEE INT C NETW