A trust management framework for Software Defined Network (SDN) controller and network applications

被引:11
|
作者
Aliyu, Aliyu Lawal [1 ]
Aneiba, Adel [1 ]
Patwary, Mohammad [1 ]
Bull, Peter [1 ]
机构
[1] Birmingham City Univ, Sch Comp & Digital Technol, Birmingham, W Midlands, England
关键词
SDN; Trust; Authentication; Authorisation; Security; SECURITY;
D O I
10.1016/j.comnet.2020.107421
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The use of network applications to manage network operations by the controller in SDN architecture introduces a threat that makes the controller to be susceptible to several network attacks. This is possible because the network applications operate without any access control mechanism that authenticates or dictates what operations they can execute in the network. This consequently makes the network applications to take advantage of their ability to manipulate, change or modify network state to compromise network operations and resources. In order to address this problem this paper introduces a token-based authentication method that enables the controller to authenticate the various network applications. The application of this method builds an access permission zone where only legitimate network applications with the correct token credentials can have access to the network prior to implementing any network changes. This paper contributes in providing an authorisation method Boolean Access Matrix that enforces permission constraints on what the network applications can access or execute within the network. The authorisation method helps limits the unprecedented access the network applications have over the control layer resources, core services and the network operations. The paper introduces a novel method of evaluating the trust between the controller and the network application based on Subjective Logic Reasoning (SLR) which is a belief learning model. SLR is an advanced learning algorithm that is derived from Probability Calculus and Statistics. Experiments demonstrate the efficiency and scalability of the proposed algorithms in a large scale test environment.
引用
收藏
页数:23
相关论文
共 50 条
  • [1] A trust management framework for software-defined network applications
    Yao, Zhen
    Yan, Zheng
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (16):
  • [2] A Trust Management Framework for Network Applications within an SDN Environment
    Aliyu, Aliyu Lawal
    Bull, Peter
    Abdallah, Ali
    2017 31ST IEEE INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS (IEEE WAINA 2017), 2017, : 93 - 98
  • [3] Control Path Management Framework for Enhancing Software-Defined Network (SDN) Reliability
    Song, Sejun
    Park, Hyungbae
    Choi, Baek-Young
    Choi, Taesang
    Zhu, Henry
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (02): : 302 - 316
  • [4] Secure Communication between Network Applications and Controller in Software Defined Network
    Aliyu, Aliyu Lawal
    Aneiba, Adel
    Patwary, Mohammad
    2019 IEEE 18TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2019, : 275 - 282
  • [5] A computationally intelligent framework for traffic engineering and congestion management in software-defined network (SDN)
    Prasanth, L. Leo
    Uma, E.
    EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2024, 2024 (01)
  • [6] Mitigating Attacks in Software Defined Network(SDN)
    Karmakar, Kallol Krishna
    Varadharajan, Vijay
    Tupakula, Udaya
    2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 112 - 117
  • [7] Trust Establishment Framework between SDN Controller and Applications
    Isong, Bassey
    Kgogo, Tebogo
    Lugayizi, Francis
    Kankuzi, Bennett
    2017 18TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNDP 2017), 2017, : 101 - 107
  • [8] Analysis of Software Defined Network (SDN) using Opendaylight Controller with ANOVA Repeated Measures
    Pullah, Rifki Izdihar Oktavian Abas
    Nugrahadi, Dodon Turianto
    Mazdadi, Muhammad Itqan
    Farmadi, Andi
    Rusadi, Ahmad
    2021 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATICS ENGINEERING (IC2IE 2021), 2021, : 323 - 327
  • [9] A Network Management Framework for SDN
    Abdallah, Sarah
    Elhajj, Imad H.
    Chehab, Ali
    Kayssi, Ayman
    2018 9TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2018,
  • [10] Taxonomy of controller placement problem (CPP) optimization in Software Defined Network (SDN): a survey
    Shirmarz, Alireza
    Ghaffari, Ali
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2021, 12 (12) : 10473 - 10498