Mitigating attacks in software defined networks

被引:17
|
作者
Karmakar, Kallol Krishna [1 ]
Varadharajan, Vijay [1 ,2 ]
Tupakula, Uday [3 ]
机构
[1] Univ Newcastle, Adv Cyber Secur Engn Res Ctr, Callaghan, NSW 2308, Australia
[2] Univ Newcastle, Adv Cyber Secur Engn Res Ctr, Cybersecur, Callaghan, NSW 2308, Australia
[3] Univ Newcastle, Sch Elect Engn & Comp, Callaghan, NSW 2308, Australia
关键词
Software defined networking (SDN) security; Threat model; Policy control;
D O I
10.1007/s10586-018-02900-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Future network innovation lies in software defined networking (SDN). This innovative technology has revolutionised the networking world for half a decade and contributes to transform legacy network architectures. This transformation blesses the networking world with improved performance and quality of service. However, security for SDN remains an afterthought. In this paper we present a detailed discussion of some of the attacks possible in SDN and techniques to deal with the attacks. The threat model will consider some significantly vulnerable areas in SDN which can lead to severe network security breaches. In particular, we describe different attacks such as attacks on the Controller, attacks on networking devices, attacks exploiting the communication links between the control plane and the data plane and different types of topology poisoning attacks. We then propose techniques to deal with some of the attacks in SDN. We make use of northbound security application on the Controller and OpenFlow agents in the networking devices for enforcing security policies in the data plane. The security application is used for specification and storage of the security policies and to make decisions on the enforcement of security policies to deal with different types of attacks. We will describe the prototype implementation of our approach using ONOS Controller and demonstrate its effectiveness against different types of attacks.
引用
收藏
页码:1143 / 1157
页数:15
相关论文
共 50 条
  • [1] Mitigating attacks in software defined networks
    Kallol Krishna Karmakar
    Vijay Varadharajan
    Uday Tupakula
    Cluster Computing, 2019, 22 : 1143 - 1157
  • [2] ISDSDN: Mitigating SYN Flood Attacks in Software Defined Networks
    Basheer Al-Duwairi
    Eslam Al-Quraan
    Yazeed AbdelQader
    Journal of Network and Systems Management, 2020, 28 : 1366 - 1390
  • [3] Bringing Intelligence to Software Defined Networks: Mitigating DDoS Attacks
    Houda, Zakaria Abou El
    Khoukhi, Lyes
    Hafid, Abdelhakim Senhaji
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (04): : 2523 - 2535
  • [4] ISDSDN: Mitigating SYN Flood Attacks in Software Defined Networks
    Al-Duwairi, Basheer
    Al-Quraan, Eslam
    AbdelQader, Yazeed
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (04) : 1366 - 1390
  • [5] Mitigating Attacks in Software Defined Network(SDN)
    Karmakar, Kallol Krishna
    Varadharajan, Vijay
    Tupakula, Udaya
    2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 112 - 117
  • [6] DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
    Li, Jishuai
    Tu, Tengfei
    Li, Yongsheng
    Qin, Sujuan
    Shi, Yijie
    Wen, Qiaoyan
    SENSORS, 2022, 22 (03)
  • [7] Detecting and Mitigating Denial of Service Attacks against the Data Plane in Software Defined Networks
    Durner, Raphael
    Lorenz, Claas
    Wiedemann, Michael
    Kellerer, Wolfgang
    2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [8] Adaptive Bubble Burst (ABB): Mitigating DDoS Attacks in Software-Defined Networks
    Sattar, Danish
    Matrawy, Ashraf
    Adeojo, Olufemi
    2016 17TH INTERNATIONAL TELECOMMUNICATIONS NETWORK STRATEGY AND PLANNING SYMPOSIUM (NETWORKS), 2016, : 50 - 55
  • [9] Detecting and Mitigating Botnet Attacks in Software-Defined Networks Using Deep Learning Techniques
    Nadeem, Muhammad Waqas
    Goh, Hock Guan
    Aun, Yichiet
    Ponnusamy, Vasaki
    IEEE ACCESS, 2023, 11 (49153-49171) : 49153 - 49171
  • [10] Mitigating Timing Side-Channel Attacks in Software-Defined Networks: Detection and Response
    Shoaib, Faizan
    Chow, Yang-Wai
    Vlahu-Gjorgievska, Elena
    Nguyen, Chau
    TELECOM, 2023, 4 (04): : 877 - 900