A comprehensive security assessment framework for software-defined networks

被引:19
|
作者
Lee, Seungsoo [1 ]
Kim, Jinwoo [2 ]
Woo, Seungwon [3 ]
Yoon, Changhoon [4 ]
Scott-Hayward, Sandra [6 ]
Yegneswaran, Vinod [5 ]
Porras, Phillip [5 ]
Shin, Seungwon [1 ,2 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Comp, Grad Sch Informat Secur, 291 Daehak Ro, Daejeon 34141, South Korea
[2] Korea Adv Inst Sci & Technol, Sch Elect Engn, 291 Daehak Ro, Daejeon 34141, South Korea
[3] ETRI, 218 Gajeong Ro, Daejeon 34129, South Korea
[4] S2W Lab, 240 Pangyoyeok Ro, Seongnam Si, South Korea
[5] SRI Int, Comp Sci Lab, 333 Ravenswood Ave, Menlo Pk, CA 94025 USA
[6] Queens Univ Belfast, Ctr Secure Informat Technol, Belfast, Antrim, North Ireland
基金
英国工程与自然科学研究理事会;
关键词
Software-Defined Networking; Security; Network security; Penetration testing;
D O I
10.1016/j.cose.2020.101720
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As Software-Defined Networking (SDN) is getting popular, its security issue is being magnified as a new controversy, and this trend can be found from recent studies of presenting possible security vulnerabilities in SDN. Understanding the attack surface of SDN is necessary, and it is the starting point to make it more secure. However, most existing studies depend on empirical methods in different environments, and thus they have stopped short of converging on a systematic methodology or developing automated systems to rigorously test for security flaws in SDNs. Therefore, we need to disclose any possible attack scenarios in diverse SDN environments and examine how these attacks operate in those environments. Inspired by the necessity for disclosing the vulnerabilities in diverse SDN operating scenarios, we suggest an SDN penetration tool, DELTA, to regenerate known attack scenarios in diverse test cases. Furthermore, DELTA can even provide a chance of discovering unknown security problems in SDN by employing a fuzzing module. In our evaluation, DELTA successfully reproduced 26 known attack scenarios, across diverse SDN controller environments, and also discovered 9 novel SDN application mislead attacks. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] SPHINX: Detecting Security Attacks in Software-Defined Networks
    Dhawan, Mohan
    Poddar, Rishabh
    Mahajan, Kshiteej
    Mann, Vijay
    22ND ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2015), 2015,
  • [22] Deep learning for the security of software-defined networks: a review
    Taheri, Roya
    Ahmed, Habib
    Arslan, Engin
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2023, 26 (05): : 3089 - 3112
  • [23] Security and performance of software-defined networks and functions virtualization
    Hausheer, David
    Hohlfeld, Oliver
    Schmid, Stefan
    Gu, Guofei
    COMPUTER NETWORKS, 2018, 138 : 15 - 17
  • [24] ANCHOR: Logically Centralized Security for Software-Defined Networks
    Kreutz, Diego
    Yu, Jiangshan
    Ramos, Fernando M. V.
    Esteves-Verissimo, Paulo
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2019, 22 (02)
  • [25] Security Framework for Internet-of-Things-Based Software-Defined Networks Using Blockchain
    Rani, Shalli
    Babbar, Himanshi
    Srivastava, Gautam
    Gadekallu, Thippa Reddy
    Dhiman, Gaurav
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (07) : 6074 - 6081
  • [26] MUD-Based Behavioral Profiling Security Framework for Software-Defined IoT Networks
    Krishnan, Prabhakar
    Jain, Kurunandan
    Buyya, Rajkumar
    Vijayakumar, Pandi
    Nayyar, Anand
    Bilal, Muhammad
    Song, Houbing
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (09) : 6611 - 6622
  • [27] AgNOS: A Framework for Autonomous Control of Software-Defined Networks
    Passito, Alexandre
    Mota, Edjard
    Bennesby, Ricardo
    Fonseca, Paulo
    2014 IEEE 28TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2014, : 405 - 412
  • [28] A Framework for Policy Inconsistency Detection in Software-Defined Networks
    Lee, Seungsoo
    Woo, Seungwon
    Kim, Jinwoo
    Nam, Jaehyun
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (03) : 1410 - 1423
  • [29] Opportunities and Challenges of Software-Defined Mobile Networks in Network Security
    Liyanage, Madhusanka
    Abro, Ahmed Bux
    Ylianttila, Mika
    Gurtov, Andrei
    IEEE SECURITY & PRIVACY, 2016, 14 (04) : 34 - 44
  • [30] A survey on software-defined vehicular networks (SDVNs): a security perspective
    Kumar, Rohit
    Agrawal, Neha
    JOURNAL OF SUPERCOMPUTING, 2023, 79 (08): : 8368 - 8400