A Taxonomy-based Approach for Security in Software-Defined Networking

被引:0
|
作者
Banse, Christian [1 ]
Schuette, Julian [1 ]
机构
[1] Fraunhofer AISEC, Garching, Germany
来源
2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC) | 2017年
关键词
taxonomy; software-defined networking; network function virtualization; logic programming;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software Defined Networking (SDN) promises to abstract hardware and hard-wired network topologies in favor of programmable dynamic infrastructures. However, especially features like multi-tenancy require for new ways to ensure that access to critical network resources are restricted to trusted applications and users. The challenge here is that these entities are not necessarily known at the time of planning and setup, but are rather added dynamically to the network at runtime. Controlling access to northbound interfaces of SDN controllers thus requires for new ways to express access control policies which are able to cope with this degree of complexity and abstraction. We thus introduce a taxonomy-based policy engine, which allows the definition of fine-grained security policies based on a first-order logic description of the network environment. We describe the taxonomy structure and show how it can be used in a Prolog-based policy engine to protect a secure SDN northbound interface developed in previous work. By evaluating the implementation in a virtual SDN environment, we found the performance overhead of our approach to be tolerable.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] A Framework for Security Services based on Software-Defined Networking
    Jeong, Jaehoon
    Seo, Jihyeok
    Cho, Geumhwan
    Kim, Hyoungshick
    Park, Jung-Soo
    2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 150 - 153
  • [2] A Survey and a Layered Taxonomy of Software-Defined Networking
    Jarraya, Yosr
    Madi, Taous
    Debbabi, Mourad
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2014, 16 (04): : 1955 - 1980
  • [3] SOFTWARE-DEFINED NETWORKING SECURITY: PROS AND CONS
    Dabbagh, Mehiar
    Hamdaoui, Bechir
    Guizani, Mohsen
    Rayes, Ammar
    IEEE COMMUNICATIONS MAGAZINE, 2015, 53 : 73 - 79
  • [4] Security Challenges and Opportunities of Software-Defined Networking
    Dacier, Marc C.
    Koenig, Hartmut
    Cwalinski, Radoslaw
    Kargl, Frank
    Dietrich, Sven
    IEEE SECURITY & PRIVACY, 2017, 15 (02) : 96 - 100
  • [5] Security in Software-Defined Networking: Threats and Countermeasures
    Shu, Zhaogang
    Wan, Jiafu
    Li, Di
    Lin, Jiaxiang
    Vasilakos, Athanasios V.
    Imran, Muhammad
    MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 764 - 776
  • [6] Software-Defined Networking (SDN): the security review
    Hussein, A.
    Chadad, Louma
    Adalian, Nareg
    Chehab, Ali
    Elhajj, Imad H.
    Kayssi, Ayman
    Journal of Cyber Security Technology, 2020, 4 (01) : 1 - 66
  • [7] Security in Software-Defined Networking: Threats and Countermeasures
    Zhaogang Shu
    Jiafu Wan
    Di Li
    Jiaxiang Lin
    Athanasios V. Vasilakos
    Muhammad Imran
    Mobile Networks and Applications, 2016, 21 : 764 - 776
  • [8] A Software-Defined Networking Security Controller Architecture
    Shang, Fengjun
    Fu, Qiang
    PROCEEDINGS OF THE 2016 4TH INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND COMPUTING TECHNOLOGY, 2016, 60 : 229 - 234
  • [9] A Software-Defined Approach to IoT Networking
    Christian Jacquenet
    Mohamed Boucadair
    ZTE Communications, 2016, 14 (01) : 61 - 66
  • [10] Security anomaly detection in software-defined networking based on a prediction technique
    Jafarian, Tohid
    Masdari, Mohammad
    Ghaffari, Ali
    Majidzadeh, Kambiz
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2020, 33 (14)