SECURING CENTRALIZED SDN CONTROL WITH DISTRIBUTED BLOCKCHAIN TECHNOLOGY

被引:1
作者
Ahmad, Suhail [1 ]
Mir, Ajaz Hussain [2 ]
机构
[1] Univ Kashmir, Dept Comp Sci & Engn, Srinagar, Jammu & Kashmir, India
[2] Natl Inst Technol, Elect & Commun Dept, Srinagar, Jammu & Kashmir, India
来源
COMPUTER SCIENCE-AGH | 2023年 / 24卷 / 01期
关键词
SDN; SDN security; blockchain; southbound interface; TLS; threats in SDNs; SOFTWARE DEFINED NETWORKS;
D O I
10.7494/csci.2023.24.1.4605
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Software-Defined Networks (SDN) advocate the segregation of network control logic, forwarding functions and management applications into different planes to achieve network programmability and automated and dynamic flow control in next-generation networks. It promotes the deployment of novel and augmented network-management functions in order to have flexible, robust, scalable, and cost-effective network deployments. All of these features introduce new rese-arch challenges and require secure communication protocols among segregated network planes. This manuscript focuses on the security issue of the south-bound interface that operates between the SDN control and the data plane. We have highlighted the security threats that are associated with an unpro-tected southbound interface and those issues that are related to the existing TLS-based security solution. A lightweight blockchain-based decentralized se-curity solution is proposed for the southbound interface to secure the resources of logically centralized SDN controllers and distributed forwarding devices from opponents. The proposed mechanism can operate in multi-domain SDN deploy-ment and can be used with a wide range of network controllers and data plane devices. In addition to this, the proposed security solution has been analyzed in terms of its security features, communication, and re-authentication overhead.
引用
收藏
页码:5 / 30
页数:26
相关论文
共 57 条
  • [1] Comparative Analysis of Control Plane Security of SDN and Conventional Networks
    Abdou, AbdelRahman
    van Oorschot, Paul C.
    Wan, Tao
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (04): : 3542 - 3559
  • [2] OpenFlow Communications and TLS Security in Software-Defined Networks
    Agborubere, Belema
    Sanchez-Velazquez, Erika
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2017, : 560 - 566
  • [3] Scalability, Consistency, Reliability and Security in SDN Controllers: A Survey of Diverse SDN Controllers
    Ahmad, Suhail
    Mir, Ajaz Hussain
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2021, 29 (01)
  • [4] A scalable, commodity data center network architecture
    Al-Fares, Mohammad
    Loukissas, Alexander
    Vahdat, Amin
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2008, 38 (04) : 63 - 74
  • [5] Identifying cyber-attacks on software defined networks: An inference-based intrusion detection approach
    AlEroud, Ahmed
    Alsmadi, Izzat
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2017, 80 : 152 - 164
  • [6] Deployment of Blockchain Technology in Software Defined Networks: A Survey
    Alharbi, Talal
    [J]. IEEE ACCESS, 2020, 8 : 9146 - 9156
  • [7] A Survey of Securing Networks Using Software Defined Networking
    Ali, Syed Taha
    Sivaraman, Vijay
    Radford, Adam
    Jha, Sanjay
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2015, 64 (03) : 1086 - 1097
  • [8] Security of Software Defined Networks: A survey
    Alsmadr, Izzat
    Xu, Dianxiang
    [J]. COMPUTERS & SECURITY, 2015, 53 : 79 - 108
  • [9] Alupotha J., 2017, 2017 IEEE INT C IND, P1
  • [10] [Anonymous], OpenFlow Switch Specification 1.5