Mitigating attacks in software defined networks

被引:17
|
作者
Karmakar, Kallol Krishna [1 ]
Varadharajan, Vijay [1 ,2 ]
Tupakula, Uday [3 ]
机构
[1] Univ Newcastle, Adv Cyber Secur Engn Res Ctr, Callaghan, NSW 2308, Australia
[2] Univ Newcastle, Adv Cyber Secur Engn Res Ctr, Cybersecur, Callaghan, NSW 2308, Australia
[3] Univ Newcastle, Sch Elect Engn & Comp, Callaghan, NSW 2308, Australia
关键词
Software defined networking (SDN) security; Threat model; Policy control;
D O I
10.1007/s10586-018-02900-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Future network innovation lies in software defined networking (SDN). This innovative technology has revolutionised the networking world for half a decade and contributes to transform legacy network architectures. This transformation blesses the networking world with improved performance and quality of service. However, security for SDN remains an afterthought. In this paper we present a detailed discussion of some of the attacks possible in SDN and techniques to deal with the attacks. The threat model will consider some significantly vulnerable areas in SDN which can lead to severe network security breaches. In particular, we describe different attacks such as attacks on the Controller, attacks on networking devices, attacks exploiting the communication links between the control plane and the data plane and different types of topology poisoning attacks. We then propose techniques to deal with some of the attacks in SDN. We make use of northbound security application on the Controller and OpenFlow agents in the networking devices for enforcing security policies in the data plane. The security application is used for specification and storage of the security policies and to make decisions on the enforcement of security policies to deal with different types of attacks. We will describe the prototype implementation of our approach using ONOS Controller and demonstrate its effectiveness against different types of attacks.
引用
收藏
页码:1143 / 1157
页数:15
相关论文
共 50 条
  • [31] Systematic Mapping on Prevention of DDoS Attacks on Software Defined Networks
    Vieira, Alfredo Menezes
    Matos Junior, Rubens de Souza
    Lima Ribeiro, Admilson de Ribamar
    2021 15TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON 2021), 2021,
  • [32] SPHINX: Detecting Security Attacks in Software-Defined Networks
    Dhawan, Mohan
    Poddar, Rishabh
    Mahajan, Kshiteej
    Mann, Vijay
    22ND ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2015), 2015,
  • [33] Detection of Distributed Denial of Service Attacks in Software Defined Networks
    Barki, Lohit
    Shidling, Amrit
    Meti, Nisharani
    Narayan, D. G.
    Mulla, Mohammed Moin
    2016 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2016, : 2576 - 2581
  • [34] Slow denial-of-service attacks on software defined networks
    Pascoal, Tulio A.
    Fonseca, Iguatemi E.
    Nigam, Vivek
    COMPUTER NETWORKS, 2020, 173
  • [35] Fast Defense System Against Attacks in Software Defined Networks
    De Assis, Marcos V. O.
    Novaes, Matheus P.
    Zerbini, Cinara B.
    Carvalho, Luiz F.
    Abrao, Taufik
    Proenca, Mario L., Jr.
    IEEE ACCESS, 2018, 6 : 69620 - 69639
  • [36] A Software Approach for Mitigation of DoS Attacks on SDN's (Software-Defined Networks)
    Lotlikar, Trupti
    Shah, Deven
    SOFT COMPUTING IN DATA ANALYTICS, SCDA 2018, 2019, 758 : 333 - 342
  • [37] Identifying DoS Attacks on Software Defined Networks : A Relation Context Approach
    Aleroud, Ahmad
    Alsmadi, Izzat
    NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 853 - 857
  • [38] Effective Topology Tampering Attacks and Defenses in Software-Defined Networks
    Skowyra, Richard
    Xu, Lei
    Gu, Guofei
    Dedhia, Veer
    Hobson, Thomas
    Okhravi, Hamed
    Landry, James
    2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2018, : 374 - 385
  • [39] Early Prevention and Mitigation of Link Flooding Attacks in Software Defined Networks
    Murtuza, Shariq
    Asawa, Krishna
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 224
  • [40] Topology Poisoning Attacks and Prevention in Hybrid Software-Defined Networks
    Shrivastava, Pragati
    Kataoka, Kotaro
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (01): : 510 - 523