Security in Software-Defined Networking: Threats and Countermeasures

被引:0
|
作者
Zhaogang Shu
Jiafu Wan
Di Li
Jiaxiang Lin
Athanasios V. Vasilakos
Muhammad Imran
机构
[1] Fujian Agriculture and Forestry University,
[2] South China University of Technology,undefined
[3] Lulea University of Technology,undefined
[4] King Saud University,undefined
来源
Mobile Networks and Applications | 2016年 / 21卷
关键词
Software-defined networking; SDN; Security; Security countermeasures;
D O I
暂无
中图分类号
学科分类号
摘要
In recent years, Software-Defined Networking (SDN) has been a focus of research. As a promising network architecture, SDN will possibly replace traditional networking, as it brings promising opportunities for network management in terms of simplicity, programmability, and elasticity. While many efforts are currently being made to standardize this emerging paradigm, careful attention needs to be also paid to security at this early design stage. This paper focuses on the security aspects of SDN. We begin by discussing characteristics and standards of SDN. On the basis of these, we discuss the security features as a whole and then analyze the security threats and countermeasures in detail from three aspects, based on which part of the SDN paradigm they target, i.e., the data forwarding layer, the control layer and the application layer. Countermeasure techniques that could be used to prevent, mitigate, or recover from some of such attacks are also described, while the threats encountered when developing these defensive mechanisms are highlighted.
引用
收藏
页码:764 / 776
页数:12
相关论文
共 50 条
  • [41] A survey on network forwarding in Software-Defined Networking
    Yang, Liang
    Ng, Bryan
    Seah, Winston K. G.
    Groves, Lindsay
    Singh, Deepak
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 176
  • [42] A Systematic Mapping About Anonymization Services For Software-Defined Networking
    Bomfim, L. H. D. S.
    Salgueiro, E. M.
    Salgueiro, R. J. P. D. B.
    Nunes, M. A. S. N.
    IEEE LATIN AMERICA TRANSACTIONS, 2017, 15 (06) : 1113 - 1120
  • [43] The KISS Principle in Software-Defined Networking: A Framework for Secure Communications
    Kreutz, Diego
    Yu, Jiangshan
    Esteves-Verissimo, Paulo
    Magalhaes, Catia
    Ramos, Fernando M., V
    IEEE SECURITY & PRIVACY, 2018, 16 (05) : 60 - 70
  • [44] A Survey on Data Plane Flexibility and Programmability in Software-Defined Networking
    Kaljic, Enio
    Maric, Almir
    Njemcevic, Pamela
    Hadzialic, Mesud
    IEEE ACCESS, 2019, 7 : 47804 - 47840
  • [45] Software-defined networking in vehicular networks: A survey
    Mekki, Tesnim
    Jabri, Issam
    Rachedi, Abderrezak
    Chaari, Lamia
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2022, 33 (10)
  • [46] Software Defined Networking: Attacks and Countermeasures
    Abd Elazim, Nada Mostafa
    Sobh, Mohamed A.
    Bahaa-Eldin, Ayman M.
    PROCEEDINGS OF 2018 13TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND SYSTEMS (ICCES), 2018, : 555 - 567
  • [47] Security anomaly detection in software-defined networking based on a prediction technique
    Jafarian, Tohid
    Masdari, Mohammad
    Ghaffari, Ali
    Majidzadeh, Kambiz
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2020, 33 (14)
  • [48] OpenSec: Policy-Based Security Using Software-Defined Networking
    Lara, Adrian
    Ramamurthy, Byrav
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2016, 13 (01): : 30 - 42
  • [49] Improving Internet of Things (IoT) Security with Software-Defined Networking (SDN)
    Al Hayajneh, Abdullah
    Bhuiyan, Md Zakirul Alam
    McAndrew, Ian
    COMPUTERS, 2020, 9 (01)
  • [50] Malicious Packet Injection on Software-Defined Networking as a Strategy to Improve Security
    Ralekgokgo, Mmamphotha Tumelo
    Velempini, Mthulisi
    Mapunya, Semaka Sekgoari
    PROCEEDINGS OF SEVENTH INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY, VOL 4, 2023, 465 : 1 - 10