A trust management framework for Software Defined Network (SDN) controller and network applications

被引:11
|
作者
Aliyu, Aliyu Lawal [1 ]
Aneiba, Adel [1 ]
Patwary, Mohammad [1 ]
Bull, Peter [1 ]
机构
[1] Birmingham City Univ, Sch Comp & Digital Technol, Birmingham, W Midlands, England
关键词
SDN; Trust; Authentication; Authorisation; Security; SECURITY;
D O I
10.1016/j.comnet.2020.107421
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The use of network applications to manage network operations by the controller in SDN architecture introduces a threat that makes the controller to be susceptible to several network attacks. This is possible because the network applications operate without any access control mechanism that authenticates or dictates what operations they can execute in the network. This consequently makes the network applications to take advantage of their ability to manipulate, change or modify network state to compromise network operations and resources. In order to address this problem this paper introduces a token-based authentication method that enables the controller to authenticate the various network applications. The application of this method builds an access permission zone where only legitimate network applications with the correct token credentials can have access to the network prior to implementing any network changes. This paper contributes in providing an authorisation method Boolean Access Matrix that enforces permission constraints on what the network applications can access or execute within the network. The authorisation method helps limits the unprecedented access the network applications have over the control layer resources, core services and the network operations. The paper introduces a novel method of evaluating the trust between the controller and the network application based on Subjective Logic Reasoning (SLR) which is a belief learning model. SLR is an advanced learning algorithm that is derived from Probability Calculus and Statistics. Experiments demonstrate the efficiency and scalability of the proposed algorithms in a large scale test environment.
引用
收藏
页数:23
相关论文
共 50 条
  • [41] Abstracting network state in Software Defined Networks (SDN) for rendezvous services
    Gurbani, Vijay K.
    Scharf, Michael
    Lakshman, T. V.
    Hilt, Volker
    Marocco, Enrico
    2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012, : 6627 - 6632
  • [42] Combined Software-Defined Network (SDN) and Internet of Things (IoT)
    Yassein, Muneer Bani
    Aljawarneh, Shadi
    Al-Rousan, Mohammad
    Mardini, Wail
    Al-Rashdan, Wesam
    2017 INTERNATIONAL CONFERENCE ON ELECTRICAL AND COMPUTING TECHNOLOGIES AND APPLICATIONS (ICECTA), 2017, : 517 - 522
  • [43] Network traffic discrimination improvement in software defined network (SDN) with deep autoencoder and ensemble method
    Shirmarz, Alireza
    Ghaffari, Ali
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2022, 14 (5) : 6321 - 6337
  • [44] Software defined network (SDN) based data server computing system
    K. Madhura
    Gillala Chandra Sekhar
    Amaresh Sahu
    M. P. Karthikeyan
    Saniya Khurana
    Meenu Shukla
    Nitish Vashisht
    International Journal of Information Technology, 2025, 17 (1) : 607 - 613
  • [45] Network traffic discrimination improvement in software defined network (SDN) with deep autoencoder and ensemble method
    Alireza Shirmarz
    Ali Ghaffari
    Journal of Ambient Intelligence and Humanized Computing, 2023, 14 : 6321 - 6337
  • [46] Software Defined Naval Network for Satellite Communications (SDN-SAT)
    Nazari, Sobhan
    Du, Pengyuan
    Gerla, Mario
    Hoffmann, Ceilidh
    Kim, Jae H.
    Capone, Antonio
    MILCOM 2016 - 2016 IEEE MILITARY COMMUNICATIONS CONFERENCE, 2016, : 360 - 366
  • [47] Demonstrating a Software Defined Network (SDN) using Carrier Ethernet Switch Routers in a Provider Network
    Gumaste, Ashwin
    Bidkar, Sarvesh
    Ghodasara, Tuneet
    Hote, Isaurabh
    Kushwaha, Anirudha
    Ambasta, Rishav
    Agrawal, Peeyush
    2015 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION (OFC), 2015,
  • [48] Pareto-Optimal Multi-Controller Placement in Software Defined Network Solving multi-controller placement problem in SDN
    Ramasamy, Mythrayee
    Pawar, Sanjay
    2018 3RD INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2018,
  • [49] A Novel Software Defined Security Framework for SDN
    Basu, Srijita
    Raun, Neha Firdaush
    Ghosal, Avishek
    Chatterjee, Debanjan
    Maitra, Debarghya
    Mazumdar, Chandan
    RISKS AND SECURITY OF INTERNET AND SYSTEMS, CRISIS 2023, 2023, 14529 : 216 - 230
  • [50] Improving Network Management with Software Defined Networking
    Kim, Hyojoon
    Feamster, Nick
    IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (02) : 114 - 119