A software defined security scheme based on SDN environment

被引:2
|
作者
Xu, Xiaolong [1 ]
Hu, Liuyun [2 ]
机构
[1] Nanjing Univ Posts & Telecommun, Sch Comp Sci, Nanjing, Jiangsu, Peoples R China
[2] Chinese Acad Sci, State Key Lab Informat Secur, Beijing, Peoples R China
来源
2017 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC) | 2017年
基金
中国国家自然科学基金;
关键词
SDN; virtualization; Software Definded Security;
D O I
10.1109/CyberC.2017.52
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper analyzes the insufficiency of traditional network architecture in the current information era firstly, and introduces the concept of Software Defined Networking (SDN). Then it describes the problems existing in the traditional security protection by analyzing the importance of network security. On the basis of SDN, the paper analyzes the effects of the SDN technology on the traditional network security protection. Along with the idea of software defined, it puts forward the concept and the main idea of software defined security. By analyzing the classic architecture of software defined network, it is concluded that SDN technology was used to construct new network architecture to realize development and application of networkvirtualization. The current new network security architectures are analyzed, and it is concluded that the current security resolution schemes cannot adapt to the development of SDN. Therefore, it is necessary to build a new security architecture, which contains centralized management based on the SDN environment. The paper makes a detailed analysis of the architecture and the internal structure of security controller in the control layer. Then according to the security mechanism, the data flow process of the network security protection is described in detail. Finally, the paper analyzes the performance of the security mechanism in three security scenes and comes up with shortage of the mechanism.
引用
收藏
页码:504 / 512
页数:9
相关论文
共 50 条
  • [41] A Software Approach for Mitigation of DoS Attacks on SDN's (Software-Defined Networks)
    Lotlikar, Trupti
    Shah, Deven
    SOFT COMPUTING IN DATA ANALYTICS, SCDA 2018, 2019, 758 : 333 - 342
  • [42] Ameliorate Security by Introducing Security Server in Software Defined Network
    Vijila, J.
    Raj, A. Albert
    CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 62 (03): : 1077 - 1096
  • [43] Security for Future Software Defined Mobile Networks
    Liyanage, Madhusanka
    Ahmad, Ijaz
    Ylianttila, Mika
    Santos, Jesus Llorente
    Kantola, Raimo
    Lopez Perez, Oscar
    Uriarte Itzazelaia, Mikel
    de Oca, Edgardo Montes
    Valtierra, Asier
    Jimenez, Carlos
    2015 9TH INTERNATIONAL CONFERENCE ON NEXT GENERATION MOBILE APPLICATIONS, SERVICES AND TECHNOLOGIES (NGMAST 2015), 2015, : 256 - 264
  • [44] A Security Services Platform for Software Defined Networks
    Tatlicioglu, Sinan
    Civanlar, Seyhan
    Gorkemli, Burak
    Lokman, Erhan
    Balci, A. Metin
    Eliacik, C. Bora
    2016 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2016, : 39 - 43
  • [45] Security Challenges in Software Defined Network and their Solutions
    Patil, Varsha
    Patil, Charulata
    Awale, R. N.
    2017 8TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2017,
  • [46] Towards security automation in Software Defined Networks
    Yungaicela-Naula, Noe M.
    Vargas-Rosales, Cesar
    Arturo Perez-Diaz, Jesus
    Zareei, Mahdi
    COMPUTER COMMUNICATIONS, 2022, 183 : 64 - 82
  • [47] The (In)Security of Topology Discovery in Software Defined Networks
    Alharbi, Talal
    Portmann, Marius
    Pakzad, Farzaneh
    40TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2015), 2015, : 502 - 505
  • [48] Enhancing Security of Software Defined Mobile Networks
    Liyanage, Madhusanka
    Ahmed, Ijaz
    Okwuibe, Jude
    Ylianttila, Mika
    Kabir, Hammad
    Santos, Jesus Llorente
    Kantola, Raimo
    Lopez Perez, Oscar
    Uriarte Itzazelaia, Mikel
    De Oca, Edgardo Monies
    IEEE ACCESS, 2017, 5 : 9422 - 9438
  • [49] A Scheme for Software Defined ORS Satellite Networking
    Feng, Jing
    Jiang, Lei
    Shen, Ye
    Ma, WeiJun
    Yin, Min
    2014 IEEE FOURTH INTERNATIONAL CONFERENCE ON BIG DATA AND CLOUD COMPUTING (BDCLOUD), 2014, : 716 - 721
  • [50] Proactive-routing path update in Software Defined Networks(SDN)
    Nadar, Shebah
    Chaudhari, Sheetal
    PROCEEDINGS OF 2017 INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND CONTROL (I2C2), 2017,