Secure and dependable software defined networks

被引:75
作者
Akhunzada, Adnan [1 ]
Gani, Abdullah [1 ]
Anuar, Nor Badrul [1 ]
Abdelaziz, Ahmed [1 ]
Khan, Muhammad Khurram [2 ]
Hayat, Amir [3 ]
Khan, Samee U. [4 ]
机构
[1] Univ Malaya, Fac Comp Sci & Informat Technol, Ctr Mobile Cloud Comp Res C4MCCR, Kuala Lumpur 50603, Malaysia
[2] King Saud Univ, CoEIA, Riyadh 11451, Saudi Arabia
[3] COMSATS Inst Informat Technol, Dept Comp Sci, Appl Secur Engn Res Grp, Islamabad, Pakistan
[4] N Dakota State Univ, Dept Elect & Comp Engn, Fargo, ND 58108 USA
关键词
Software defined networks; Programmable networks; Open Flow; Policy enforcement; Middle-boxes; CHALLENGES; TAXONOMY; FUTURE;
D O I
10.1016/j.jnca.2015.11.012
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The revolutionary concept of Software Defined Networks (SDNs) potentially provides flexible and well-managed next-generation networks. All the hype surrounding the SDNs is predominantly because of its centralized management functionality, the separation of the control plane from the data forwarding plane, and enabling innovation through network programmability. Despite the promising architecture of SDNs, security was not considered as part of the initial design. Moreover, security concerns are potentially augmented considering the logical centralization of network intelligence. Furthermore, the security and dependability of the SDN has largely been a neglected topic and remains an open issue. The paper presents a broad overview of the security implications of each SDN layer/interface. This paper contributes further by devising a contemporary layered/interface taxonomy of the reported security vulnerabilities, attacks, and challenges of SDN. We also highlight and analyze the possible threats on each layer/interface of SDN to help design secure SDNs. Moreover, the ensuing paper contributes by presenting the state-of-the-art SDNs security solutions. The categorization of solutions is followed by a critical analysis and discussion to devise a comprehensive thematic taxonomy. We advocate the production of secure and dependable SDNs by presenting potential requirements and key enablers. Finally, in an effort to anticipate secure and dependable SDNs, we present the ongoing open security issues, challenges and future research directions. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:199 / 221
页数:23
相关论文
共 148 条
  • [1] Ahmad RW, 2015, J NETW COMPUT APPL
  • [2] Securing Software Defined Networks: Taxonomy, Requirements, and Open Issues
    Akhunzada, Adnan
    Ahmed, Ejaz
    Gani, Abdullah
    Khan, Muhammad Khurram
    Imran, Muhammad
    Guizani, Sghaier
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (04) : 36 - 44
  • [3] Man-At-The-End attacks: Analysis, taxonomy, human aspects, motivation and future directions
    Akhunzada, Adnan
    Sookhak, Mehdi
    Anuar, Nor Badrul
    Gani, Abdullah
    Ahmed, Ejaz
    Shiraz, Muhammad
    Furnell, Steven
    Hayat, Amir
    Khan, Muhammad Khurram
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2015, 48 : 44 - 57
  • [4] Al-Shabibi A, 2014, P 3 ACM WORKSH HOT T
  • [5] Al-Shaer E., 2010, P 3 ACM WORKSHOP ASS, P37, DOI DOI 10.1145/1866898.1866905
  • [6] Al-Shaer E, 2009, P 17 IEEE INT C NETW
  • [7] Impact analysis and change propagation in service-oriented enterprises: A systematic review
    Alam, Khubaib Amjad
    Ahmad, Rodina
    Akhunzada, Adnan
    Nasir, Mohd Hairul Nizam Md
    Khan, Samee U.
    [J]. INFORMATION SYSTEMS, 2015, 54 : 43 - 73
  • [8] Ali ST, 2014, IEEE T RELIAB
  • [9] [Anonymous], 2013, P 2 ACM SIGCOMM WORK, DOI DOI 10.1145/2491185.2491199
  • [10] [Anonymous], 2013, SPEC VERS O S 1 4 0