Mitigating attacks in software defined networks

被引:17
|
作者
Karmakar, Kallol Krishna [1 ]
Varadharajan, Vijay [1 ,2 ]
Tupakula, Uday [3 ]
机构
[1] Univ Newcastle, Adv Cyber Secur Engn Res Ctr, Callaghan, NSW 2308, Australia
[2] Univ Newcastle, Adv Cyber Secur Engn Res Ctr, Cybersecur, Callaghan, NSW 2308, Australia
[3] Univ Newcastle, Sch Elect Engn & Comp, Callaghan, NSW 2308, Australia
关键词
Software defined networking (SDN) security; Threat model; Policy control;
D O I
10.1007/s10586-018-02900-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Future network innovation lies in software defined networking (SDN). This innovative technology has revolutionised the networking world for half a decade and contributes to transform legacy network architectures. This transformation blesses the networking world with improved performance and quality of service. However, security for SDN remains an afterthought. In this paper we present a detailed discussion of some of the attacks possible in SDN and techniques to deal with the attacks. The threat model will consider some significantly vulnerable areas in SDN which can lead to severe network security breaches. In particular, we describe different attacks such as attacks on the Controller, attacks on networking devices, attacks exploiting the communication links between the control plane and the data plane and different types of topology poisoning attacks. We then propose techniques to deal with some of the attacks in SDN. We make use of northbound security application on the Controller and OpenFlow agents in the networking devices for enforcing security policies in the data plane. The security application is used for specification and storage of the security policies and to make decisions on the enforcement of security policies to deal with different types of attacks. We will describe the prototype implementation of our approach using ONOS Controller and demonstrate its effectiveness against different types of attacks.
引用
收藏
页码:1143 / 1157
页数:15
相关论文
共 50 条
  • [41] A Testbed for the Evaluation of Denial of Service Attacks in Software-Defined Networks
    Wright, Andrea P.
    Ghani, Nasir
    2019 IEEE SOUTHEASTCON, 2019,
  • [42] Control Plane Reflection Attacks and Defenses in Software-Defined Networks
    Zhang, Menghao
    Li, Guanyu
    Xu, Lei
    Bai, Jiasong
    Xu, Mingwei
    Gu, Guofei
    Wu, Jianping
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2021, 29 (02) : 623 - 636
  • [43] Counteracting Attacks From Malicious End Hosts in Software Defined Networks
    Varadharajan, Vijay
    Tupakula, Uday
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 160 - 174
  • [44] Network fingerprinting via timing attacks and defense in software defined networks
    Yigit, Beytullah
    Gur, Gurkan
    Alagoz, Fatih
    Tellenbach, Bernhard
    COMPUTER NETWORKS, 2023, 232
  • [45] Detection of DHCP Starvation Attacks in Software Defined Networks: A Case Study
    Toprak, Cansu
    Turker, Cem
    Erman, Aysegul Tuysuz
    2018 3RD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ENGINEERING (UBMK), 2018, : 636 - 641
  • [46] An approach to detecting distributed denial of service attacks in software defined networks
    Sangodoyin, Abimbola
    Modu, Babagana
    Awan, Irfan
    Disso, Jules Pagna
    2018 IEEE 6TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2018), 2018, : 436 - 443
  • [47] Detection and Prevention of DoS attacks in Software-Defined Cloud Networks
    Rengaraju, Perumalraja
    Ramanan, Raja, V
    Lung, Chung-Horng
    2017 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING, 2017, : 217 - 223
  • [48] Detection and Mitigation of ARP Storm Attacks using Software Defined Networks
    Numan, Munther
    Hashim, Fazirulhisyam
    Latiff, Nurul Adilah Abdul
    2017 IEEE 13TH MALAYSIA INTERNATIONAL CONFERENCE ON COMMUNICATIONS (MICC), 2017, : 181 - 186
  • [49] A GRU deep learning system against attacks in software defined networks
    Assis, Marcos V. O.
    Carvalho, Luiz F.
    Lloret, Jaime
    Proenca, Mario L.
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 177
  • [50] Detecting and mitigating cyberattacks using software defined networks for integrated clinical environments
    Celdran, Alberto Huertas
    Karmakar, Kallol Krishna
    Marmol, Felix Gomez
    Varadharajan, Vijay
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2021, 14 (05) : 2719 - 2734