AuthFlow: authentication and access control mechanism for software defined networking

被引:0
作者
Diogo Menezes Ferrazani Mattos
Otto Carlos Muniz Bandeira Duarte
机构
[1] Universidade Federal do Rio de Janeiro (COPPE/UFRJ),Grupo de Teleinformática e Automação
[2] Sorbonne Universities,Laboratoire d’Informatique de Paris 6
来源
Annals of Telecommunications | 2016年 / 71卷
关键词
Access control; Authentication; Software-defined networking;
D O I
暂无
中图分类号
学科分类号
摘要
Software-defined networking (SDN) is being widely adopted by enterprise networks, whereas providing security features in these next generation networks is a challenge. In this article, we present the main security threats in software-defined networking and we propose AuthFlow, an authentication and access control mechanism based on host credentials. The main contributions of our proposal are threefold: (i) a host authentication mechanism just above the MAC layer in an OpenFlow network, which guarantees a low overhead and ensures a fine-grained access control; (ii) a credential-based authentication to perform an access control according to the privilege level of each host, through mapping the host credentials to the set of flows that belongs to the host; (iii) a new framework for control applications, enabling software-defined network controllers to use the host identity as a new flow field to define forwarding rules. A prototype of the proposed mechanism was implemented on top of POX controller. The results show that AuthFlow denies the access of hosts either without valid credentials or with revoked authorization. Finally, we show that our scheme allows, for each host, different levels of access to network resources according to its credential.
引用
收藏
页码:607 / 615
页数:8
相关论文
共 45 条
[1]  
Casado M(2007)Ethane: taking control of the enterprise ACM SIGCOMM Comput Commun Rev 37 1-12
[2]  
Freedman M(2011)Virtual networks: isolation, performance, and trends Ann Telecommun 66 339-355
[3]  
Pettit J(2014)On the testing of network cyber threat detection methods on spam example Ann. Telecommun 69 363-377
[4]  
Luo J(2010)Intelligent agents in home healthcare Ann Telecommun 65 593-600
[5]  
McKeown N(2014)Maturing of OpenFlow and software-defined networking through deployments Comput Netw 61 151-175
[6]  
Shenker S(2015)Software-defined networking: a comprehensive survey Proc IEEE 103 14-76
[7]  
Fernandes NC(2014)FITS: a flexible virtual network testbed architecture Computer Networks 63 221-237
[8]  
Moreira MDD(undefined)undefined undefined undefined undefined-undefined
[9]  
Moraes IM(undefined)undefined undefined undefined undefined-undefined
[10]  
Ferraz LHG(undefined)undefined undefined undefined undefined-undefined