A comprehensive security assessment framework for software-defined networks

被引:19
|
作者
Lee, Seungsoo [1 ]
Kim, Jinwoo [2 ]
Woo, Seungwon [3 ]
Yoon, Changhoon [4 ]
Scott-Hayward, Sandra [6 ]
Yegneswaran, Vinod [5 ]
Porras, Phillip [5 ]
Shin, Seungwon [1 ,2 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Comp, Grad Sch Informat Secur, 291 Daehak Ro, Daejeon 34141, South Korea
[2] Korea Adv Inst Sci & Technol, Sch Elect Engn, 291 Daehak Ro, Daejeon 34141, South Korea
[3] ETRI, 218 Gajeong Ro, Daejeon 34129, South Korea
[4] S2W Lab, 240 Pangyoyeok Ro, Seongnam Si, South Korea
[5] SRI Int, Comp Sci Lab, 333 Ravenswood Ave, Menlo Pk, CA 94025 USA
[6] Queens Univ Belfast, Ctr Secure Informat Technol, Belfast, Antrim, North Ireland
基金
英国工程与自然科学研究理事会;
关键词
Software-Defined Networking; Security; Network security; Penetration testing;
D O I
10.1016/j.cose.2020.101720
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As Software-Defined Networking (SDN) is getting popular, its security issue is being magnified as a new controversy, and this trend can be found from recent studies of presenting possible security vulnerabilities in SDN. Understanding the attack surface of SDN is necessary, and it is the starting point to make it more secure. However, most existing studies depend on empirical methods in different environments, and thus they have stopped short of converging on a systematic methodology or developing automated systems to rigorously test for security flaws in SDNs. Therefore, we need to disclose any possible attack scenarios in diverse SDN environments and examine how these attacks operate in those environments. Inspired by the necessity for disclosing the vulnerabilities in diverse SDN operating scenarios, we suggest an SDN penetration tool, DELTA, to regenerate known attack scenarios in diverse test cases. Furthermore, DELTA can even provide a chance of discovering unknown security problems in SDN by employing a fuzzing module. In our evaluation, DELTA successfully reproduced 26 known attack scenarios, across diverse SDN controller environments, and also discovered 9 novel SDN application mislead attacks. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] DELTA: A Security Assessment Framework for Software-Defined Networks
    Lee, Seungsoo
    Yoon, Changhoon
    Lee, Chanhee
    Shin, Seungwon
    Yegneswaran, Vinod
    Porras, Phillip
    24TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2017), 2017,
  • [2] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [3] A security and trust framework for virtualized networks and software-defined networking
    Yan, Zheng
    Zhang, Peng
    Vasilakos, Athanasios V.
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (16) : 3059 - 3069
  • [4] A Collaborative Security Framework for Software-Defined Wireless Sensor Networks
    Miranda, Christian
    Kaddoum, Georges
    Bou-Harb, Elias
    Garg, Sahil
    Kaur, Kuljeet
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 2602 - 2615
  • [5] Software-Defined Mobile Networks Security
    Min Chen
    Yongfeng Qian
    Shiwen Mao
    Wan Tang
    Ximin Yang
    Mobile Networks and Applications, 2016, 21 : 729 - 743
  • [6] Security Evaluation in Software-Defined Networks
    Ivkic, Igor
    Thiede, Dominik
    Race, Nicholas
    Broadbent, Matthew
    Gouglidis, Antonios
    CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2022, CLOSER 2023, 2024, 1845 : 66 - 91
  • [7] Software-Defined Mobile Networks Security
    Chen, Min
    Qian, Yongfeng
    Mao, Shiwen
    Tang, Wan
    Yang, Ximin
    MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 729 - 743
  • [8] SDSA: A Framework of a Software-Defined Security Architecture
    Liu Yanbing
    Lu Xingyu
    Jian Yi
    Xiao Yunpeng
    CHINA COMMUNICATIONS, 2016, 13 (02) : 178 - 188
  • [9] Improving the Routing Security in Software-Defined Networks
    Ai, Jianjian
    Guo, Zehua
    Chen, Hongchang
    Cheng, Guozhen
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (05) : 838 - 841
  • [10] Semantic Security Tools in Software-Defined Networks
    Antoshina, E. Ju.
    Chalyy, D. Ju.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2018, 52 (07) : 605 - 607