Security in OpenFlow-based SDN, opportunities and challenges

被引:12
作者
Benabbou, Jaouad [1 ]
Elbaamrani, Khalid [1 ]
Idboufker, Noureddine [1 ]
机构
[1] Cadi Ayyad Univ, ENSA Marrakech, Network & Telecommun Dept, Marrakech, Morocco
关键词
Security; SDN; OpenFlow; Availability; Access control; Recovery; SOFTWARE; MECHANISM; NETWORKS; FLOW;
D O I
10.1007/s11107-018-0803-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The SDN paradigm profoundly affects the architecture of networks in favor of more adaptability to the needs for new value-added services. This article examines the positive and negative impacts of such a change on network security. While few in-depth studies have attempted to cover this issue in a comprehensive way, we first tried to define the most relevant axes of analyses with regard to this concept, namely availability, access control and application services oriented security. In relation to these axes as well as to the state of the art of security, a number of researches and studies that have addressed this issue by proposing solutions through the OpenFlow specification are analyzed with the aim to highlight the real opportunities and the real challenges brought by this new concept for the network security.
引用
收藏
页码:1 / 23
页数:23
相关论文
共 69 条
[1]   Security in Software Defined Networks: A Survey [J].
Ahmad, Ijaz ;
Namal, Suneth ;
Ylianttila, Mika ;
Gurtov, Andrei .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04) :2317-2346
[2]   A Survey of Securing Networks Using Software Defined Networking [J].
Ali, Syed Taha ;
Sivaraman, Vijay ;
Radford, Adam ;
Jha, Sanjay .
IEEE TRANSACTIONS ON RELIABILITY, 2015, 64 (03) :1086-1097
[3]  
[Anonymous], USENIX SEC S
[4]  
[Anonymous], 2013, Proceedings of the second ACM SIGCOMM workshop on hot topics in software defined networking, DOI DOI 10.1145/2491185.2491222
[5]  
[Anonymous], 2013, P 2013 IEEE SDN FUTU
[6]  
[Anonymous], 2015, P 2015 NETW DISTR SY
[7]  
[Anonymous], HOTSDN 13
[8]  
[Anonymous], 2015, TR511 ONF
[9]  
[Anonymous], 2015, P 45 ANN IEEE IFIP I
[10]  
[Anonymous], 2012, 9 USENIX C NETW SYST