On the Design and Implementation of a Security Architecture for Software Defined Networks

被引:0
作者
Karmakar, Kallol Krishna [1 ]
Varadharajan, Vijay [1 ]
Tupakula, Udaya [1 ]
机构
[1] Macquarie Univ, Fac Sci, Adv Cyber Secur Res Ctr, Sydney, NSW, Australia
来源
PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS) | 2016年
关键词
Software Defined Networking (SDN) Security; OpenFlow; ACL; Source Spoofing; Policy Control;
D O I
10.1109/HPCC-SmartCity-DSS.2016.138
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose techniques for securing Software Defined Networks(SDN). We describe the design of a security architecture that makes use of security applications on top of the SDN Controller to specify fine granular security policies based on domain wide knowledge of the domain and Security Agents to enforce these policies in the switches in the data plane. We have extended the Open Flow protocol to enable communication of the security policies between the security applications in the Controller to the agents in the switches. We have implemented the security architecture using POX Controller and demonstrated the operation of our architecture in a range of scenarios such as enforcing specific security policies for different traffic with different services, counteracting attacks such as Heartbleed and Shellshock as well as spoofing attacks, and protecting Content Management Systems(CMS) from data confidentiality attacks.
引用
收藏
页码:671 / 678
页数:8
相关论文
共 20 条
[1]  
[Anonymous], 2013, P 2 ACM SIGCOMM WORK, DOI DOI 10.1145/2491185.2491199
[2]  
[Anonymous], 2016, SYMANTEC INTERBET SE
[3]  
[Anonymous], SOURCE ADDRESS VALID
[4]  
[Anonymous], 2005, Iperf: The TCP/UDP Bandwidth Mea- surement Tool
[5]  
[Anonymous], SIGCOMM COMPUT COMMU
[6]   Frenetic: A Network Programming Language [J].
Foster, Nate ;
Harrison, Rob ;
Freedman, Michael J. ;
Monsanto, Christopher ;
Rexford, Jennifer ;
Story, Alec ;
Walker, David .
ACM SIGPLAN NOTICES, 2011, 46 (09) :279-291
[7]  
Grossman J., 2013, WHITEHAT SECURITY WE, V12
[8]  
Guang Yao, 2011, 2011 19th IEEE International Conference on Network Protocols, P7, DOI 10.1109/ICNP.2011.6089085
[9]  
Hinrichs TL, 2009, WREN 2009, P1
[10]  
Ht bridge, 2014, HIGH TECH BRIDG RES