A software defined security scheme based on SDN environment

被引:2
|
作者
Xu, Xiaolong [1 ]
Hu, Liuyun [2 ]
机构
[1] Nanjing Univ Posts & Telecommun, Sch Comp Sci, Nanjing, Jiangsu, Peoples R China
[2] Chinese Acad Sci, State Key Lab Informat Secur, Beijing, Peoples R China
来源
2017 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC) | 2017年
基金
中国国家自然科学基金;
关键词
SDN; virtualization; Software Definded Security;
D O I
10.1109/CyberC.2017.52
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper analyzes the insufficiency of traditional network architecture in the current information era firstly, and introduces the concept of Software Defined Networking (SDN). Then it describes the problems existing in the traditional security protection by analyzing the importance of network security. On the basis of SDN, the paper analyzes the effects of the SDN technology on the traditional network security protection. Along with the idea of software defined, it puts forward the concept and the main idea of software defined security. By analyzing the classic architecture of software defined network, it is concluded that SDN technology was used to construct new network architecture to realize development and application of networkvirtualization. The current new network security architectures are analyzed, and it is concluded that the current security resolution schemes cannot adapt to the development of SDN. Therefore, it is necessary to build a new security architecture, which contains centralized management based on the SDN environment. The paper makes a detailed analysis of the architecture and the internal structure of security controller in the control layer. Then according to the security mechanism, the data flow process of the network security protection is described in detail. Finally, the paper analyzes the performance of the security mechanism in three security scenes and comes up with shortage of the mechanism.
引用
收藏
页码:504 / 512
页数:9
相关论文
共 50 条
  • [21] A novel Security Mechanism for Software Defined Network Based on Blockchain
    Guo, Xian
    Wang, Chen
    Cao, Laicheng
    Jiang, Yongbo
    Yan, Yan
    COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2022, 19 (02) : 523 - 545
  • [22] Multilevel Security Framework for NFV Based on Software Defined Perimeter
    Singh, Jaspreet
    Refaey, Ahmed
    Shami, Abdallah
    IEEE NETWORK, 2020, 34 (05): : 114 - 119
  • [23] A hierarchical mobility management scheme based on software defined networking
    Xing Yin
    Liangmin Wang
    Shunrong Jiang
    Peer-to-Peer Networking and Applications, 2019, 12 : 310 - 325
  • [24] On SDPN: Integrating the Software-Defined Perimeter (SDP) and the Software-Defined Network (SDN) Paradigms
    Lefebvre, Michael
    Engels, Daniel W.
    Nair, Suku
    2022 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2022, : 353 - 358
  • [25] A hierarchical mobility management scheme based on software defined networking
    Yin, Xing
    Wang, Liangmin
    Jiang, Shunrong
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2019, 12 (02) : 310 - 325
  • [26] Data Center Optical Networks (DCON) with OpenFlow based Software Defined Networking (SDN)
    Zhao, Yongli
    Zhang, Jie
    Yang, Hui
    Yu, Xiaosong
    2013 8TH INTERNATIONAL ICST CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA (CHINACOM), 2013, : 771 - 775
  • [27] A Survey of Security in Software Defined Networks
    Scott-Hayward, Sandra
    Natarajan, Sriram
    Sezer, Sakir
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2016, 18 (01): : 623 - 654
  • [28] Security in Software Defined Networks: A Survey
    Ahmad, Ijaz
    Namal, Suneth
    Ylianttila, Mika
    Gurtov, Andrei
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04): : 2317 - 2346
  • [29] Software Defined IoT Security Framework
    Salman, Ola
    Elhajj, Imad
    Chehab, Ali
    Kayssi, Ayman
    2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 75 - 80
  • [30] The (In)Security of Virtualization in Software Defined Networks
    Alharbi, Talal
    Portmann, Marius
    IEEE ACCESS, 2019, 7 : 66584 - 66594