A trust management framework for Software Defined Network (SDN) controller and network applications

被引:11
|
作者
Aliyu, Aliyu Lawal [1 ]
Aneiba, Adel [1 ]
Patwary, Mohammad [1 ]
Bull, Peter [1 ]
机构
[1] Birmingham City Univ, Sch Comp & Digital Technol, Birmingham, W Midlands, England
关键词
SDN; Trust; Authentication; Authorisation; Security; SECURITY;
D O I
10.1016/j.comnet.2020.107421
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The use of network applications to manage network operations by the controller in SDN architecture introduces a threat that makes the controller to be susceptible to several network attacks. This is possible because the network applications operate without any access control mechanism that authenticates or dictates what operations they can execute in the network. This consequently makes the network applications to take advantage of their ability to manipulate, change or modify network state to compromise network operations and resources. In order to address this problem this paper introduces a token-based authentication method that enables the controller to authenticate the various network applications. The application of this method builds an access permission zone where only legitimate network applications with the correct token credentials can have access to the network prior to implementing any network changes. This paper contributes in providing an authorisation method Boolean Access Matrix that enforces permission constraints on what the network applications can access or execute within the network. The authorisation method helps limits the unprecedented access the network applications have over the control layer resources, core services and the network operations. The paper introduces a novel method of evaluating the trust between the controller and the network application based on Subjective Logic Reasoning (SLR) which is a belief learning model. SLR is an advanced learning algorithm that is derived from Probability Calculus and Statistics. Experiments demonstrate the efficiency and scalability of the proposed algorithms in a large scale test environment.
引用
收藏
页数:23
相关论文
共 50 条
  • [21] Software Defined Network Based Management Framework For Wireless Sensor Networks
    Tadros, Catherine Nayer
    Mokhtar, Bassem
    Rizk, Mohamed R. M.
    2018 IEEE 9TH ANNUAL INFORMATION TECHNOLOGY, ELECTRONICS AND MOBILE COMMUNICATION CONFERENCE (IEMCON), 2018, : 1200 - 1205
  • [22] AN ACTIVE QUEUE MANAGEMENT ADAPTATION FRAMEWORK FOR SOFTWARE DEFINED OPTICAL NETWORK
    Ge, Zhaozhi
    Gu, Rentao
    Ji, Yuefeng
    2014 13TH INTERNATIONAL CONFERENCE ON OPTICAL COMMUNICATIONS AND NETWORKS (ICOCN), 2014,
  • [23] A Novel Secure and Efficient Policy Management Framework for Software Defined Network
    Tripathy, Bata Krishna
    Sethy, Ananta Gopal
    Bera, Padmalochan
    Rahman, Mohammad Ashiqur
    PROCEEDINGS 2016 IEEE 40TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC), VOL 2, 2016, : 423 - 430
  • [24] Disaster Information Network based on Software Defined Network Framework
    Sekin, Yuto
    Uchida, Noriki
    Shibata, Yoshitaka
    Shiratori, Norio
    2013 IEEE 27TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS (WAINA), 2013, : 237 - 242
  • [25] Enhancing Network Security through Software Defined Networking (SDN)
    Shin, Seungwon
    Xu, Lei
    Hong, Sungmin
    Gu, Guofei
    2016 25TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN), 2016,
  • [26] A Heuristic Approach for the CCLP Problem in Software Defined Network (SDN)
    Veeramani, S.
    Mahammad, Noor Sk
    INTERNETWORKING INDONESIA, 2018, 10 (01): : 3 - 8
  • [27] Software Defined Networking (SDN) and Network Function Virtualization (NFV)
    Papavassiliou, Symeon
    FUTURE INTERNET, 2020, 12 (01):
  • [28] Future Technology: Software-Defined Network (SDN) Forensic
    Waseem, Quadri
    Alshamrani, Sultan S.
    Nisar, Kashif
    Wan Din, Wan Isni Sofiah
    Alghamdi, Ahmed Saeed
    SYMMETRY-BASEL, 2021, 13 (05):
  • [29] Trust Support for SDN Controllers and Virtualized Network Applications
    Betge-Brezetz, Stephane
    Kamga, Guy-Bertrand
    Tazi, Monsef
    2015 1ST IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT), 2015,
  • [30] "Common Criteria" and Software-Defined Network (SDN) Security
    Mukhanov, A.
    Petukhov, A.
    Pilugin, P.
    2018 INTERNATIONAL SCIENTIFIC AND TECHNICAL CONFERENCE MODERN COMPUTER NETWORK TECHNOLOGIES (MONETEC 2018), 2018,