SENAD: Securing Network Application Deployment in Software Defined Networks

被引:0
|
作者
Tseng, Yuchia [1 ]
Nait-Abdesselam, Farid [2 ]
Khokhar, Ashfaq [3 ]
机构
[1] Paris Descartes Univ, IRT Syst X, Paris, France
[2] Paris Descartes Univ, Paris, France
[3] Iowa State Univ, Ames, IA USA
来源
2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC) | 2018年
关键词
SDN controller; network applications; security-by-design;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The Software Defined Networks (SDN) paradigm, often referred to as a radical new idea in networking, promises to dramatically simplify network management by enabling innovation through network programmability. However, notable security issues, such as app-to-control threats, remain a significant concern that impedes SDN from being widely adopted. To cope with those app-to-control threats, this paper proposes a solution to securely deploy valid network applications while protecting the SDN controller against the injection of the malicious application. This problem is mitigated by proposing a novel SDN architecture, dubbed SENAD, which splits the well-known SDN controller into: (1) a data plane controller (DPC), and (2) an application plane controller (APC), to secure this latter by design. The role of the DPC is dedicated for interpreting the network rules into OpenFlow entries and maintaining the communication with the data plane. The role of the APC, however, is to provide a secured runtime for deploying the network applications, including authentication, access control, resource isolation, control, and monitoring applications. We show that this approach can easily shield against any deny of service, caused for instance by the resource exhaustion attack or the malicious command injection, that is caused by the co-existence of a malicious application on the controller's runtime. The evaluation of our architecture shows that the packet_in messages take less than 5 ms to be delivered from the data plane to the application plane on the long range.
引用
收藏
页数:6
相关论文
共 30 条
  • [1] Programming the Network: Application Software Faults in Software-Defined Networks
    Jagadeesan, Lalita J.
    Mendiratta, Veena
    2016 IEEE 27TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW), 2016, : 125 - 131
  • [2] An approach for deployment of BRS in software-defined network
    Dutta, Parinita
    Chatterjee, Rajeev
    Mandal, Jyotsna Kumar
    INNOVATIONS IN SYSTEMS AND SOFTWARE ENGINEERING, 2019, 15 (3-4) : 355 - 361
  • [3] An approach for deployment of BRS in software-defined network
    Parinita Dutta
    Rajeev Chatterjee
    Jyotsna Kumar Mandal
    Innovations in Systems and Software Engineering, 2019, 15 : 355 - 361
  • [4] SDNMA: A Software-defined, Dynamic Network Manipulation Application to Enhance BGP Functionality
    Gandotra, Rahil
    Perigo, Levi
    IEEE 20TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS / IEEE 16TH INTERNATIONAL CONFERENCE ON SMART CITY / IEEE 4TH INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2018, : 1007 - 1014
  • [5] Efficient Topology Discovery in Software Defined Networks: Revisited
    Hasan, Dana
    Othman, Mohamed
    DISCOVERY AND INNOVATION OF COMPUTER SCIENCE TECHNOLOGY IN ARTIFICIAL INTELLIGENCE ERA, 2017, 116 : 539 - 547
  • [6] SDN Cluster Constructor: Software Toolkit for Structures Segmentation of Software Defined Networks
    Perepelkin, Dmitry
    Tsyganov, Ilya
    2019 XVI INTERNATIONAL SYMPOSIUM PROBLEMS OF REDUNDANCY IN INFORMATION AND CONTROL SYSTEMS (REDUNDANCY), 2019, : 195 - 198
  • [7] Improvement of the Handover and Quality of Service on Software Defined Wireless Networks
    Laassiri, Fatima
    Moughit, Mohamed
    Idboufker, Noureddine
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2018, 9 (12) : 94 - 98
  • [8] Performance evaluation of centralised and distributed controllers in software defined networks
    Hassen, Houda
    Meherzi, Soumaya
    International Journal of Wireless and Mobile Computing, 2024, 27 (02) : 103 - 117
  • [9] A Self-Routing Technique for Software-Defined Networks
    Almohaimeed, Abdulrahman
    Abu Asaduzzaman
    2019 IEEE SOUTHEASTCON, 2019,
  • [10] Development and Implementation of Enhanced Segmentation Algorithm in Software Defined Networks
    Perepelkin, Dmitry
    Tsyganov, Ilya
    2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2019, : 19 - 23