Secured Communication Channels in Software-Defined Networks

被引:14
作者
Yigit, Beytullah [1 ]
Gur, Gurkan [2 ]
Tellenbach, Bernhard [2 ]
Alagoz, Fatih [1 ]
机构
[1] Bogazici Univ, Dept Comp Engn, Istanbul, Turkey
[2] Zurich Univ Appl Sci, Winterthur, Switzerland
关键词
Software defined networking; Network function virtualization; Erbium-doped fiber lasers; Photonics; Laser mode locking; Laser theory; Optical fiber polarization;
D O I
10.1109/MCOM.001.1900060
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
SDN brings new opportunities to alleviate the existing security deficiencies of traditional networks. However, it also introduces new issues, a primary one being the vulnerabilities related to data and control plane communications. This work presents a security architecture to address security problems regarding data exchange in software-defined networks. To this end, a cryptographic key generation application is proposed to generate certificates that are used for securing communication of SDN entities (controller, switch, and application). We also provide an overview of related literature focusing on key elements in such architecture. In our model, TLS can be activated between SDN nodes to provide confidentiality, integrity, authentication, and authorization with special certificate fields. Besides, an integrated security module further strengthens the communication security by applying ACL, hardening TLS configuration and reducing the impact of private key hijacking. It also facilitates security administration tasks via per-channel activation/ deactivation of TLS protocol and monitoring of real-time security alarms.
引用
收藏
页码:63 / 69
页数:7
相关论文
共 15 条
[1]   OpenFlow Communications and TLS Security in Software-Defined Networks [J].
Agborubere, Belema ;
Sanchez-Velazquez, Erika .
2017 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2017, :560-566
[2]   A Secure Northbound Interface for SDN Applications [J].
Banse, Christian ;
Rangarajan, Sathyanarayanan .
2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, :834-839
[3]  
Cui HY, 2017, INT SYMP WIREL, P1, DOI 10.1109/WPMC.2017.8301788
[4]   Research Trends in Security and DDoS in SDN [J].
Dayal, Neelam ;
Maity, Prasenjit ;
Srivastava, Shashank ;
Khondoker, Rahamatullah .
SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) :6386-6411
[5]   Study on Algorithm of Image Restoration Based on Stochastic Resonance and Wavelet Transforming [J].
Jiang, Yuan ;
Peng, Yue Ping ;
Wang, Jian .
PROCEEDINGS OF 2016 SIXTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION & MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC 2016), 2016, :416-421
[6]  
Kang J. W., 2015, 2015 24 INT C COMPUT
[7]  
Kreutz D., 2013, Proc. Second ACM SIGCOMM Work. Hot Top. Softw. Defin. Netw. - HotSDN'13, DOI DOI 10.1145/2491185.2491199
[8]  
Lam J., 2016, MOBILE INFO SYSTEMS, V2016
[9]   TLS Channel Implementation for ONOS's East/West-Bound Communication [J].
Lam, Jun Huy ;
Lee, Sang-Gon ;
Lee, Hoon-Jae ;
Oktian, Yustus Eko .
ELECTRONICS, COMMUNICATIONS AND NETWORKS V, 2016, 382 :397-403
[10]  
Liyanage M., 2014, PROCEEDING IEEE INT, DOI [10.1109/WoWMoM.2014.6918981, DOI 10.1109/WOWMOM.2014.6918981]