A novel security mechanism for software defined network based on Blockchain

نویسندگان

چکیده

The decoupling of the data plane and control in Software- Defined Network (SDN) can increase flexibility network management operation. And it reduce limitations caused by hardware. However, centralized scheme SDN also introduce some other security issues such as single point failure, consistency multiple-controller environment spoofing attack initiated a malicious device plane. To solve these problems, framework for based on Blockchain (BCSDN) is proposed this paper. BCSDN adopts physically distributed logically multi-controller architecture. LLDP protocol periodically used to obtain link state information network, Merkle tree establised according collected signature generate KSI each that submitted switch main controller selected using PoW mechanism. Such, dynamic change topology recorded Blockchian among multiple controllers be guaranteed. corresponding checks legitimate verifying when requests flow rule table from later. verification ensures authenticated communication between switch. Finally, simulation new implemented Mininet platform emulation experiments are done verify our novel solution tool. we informally analysis attributes provided BCSDN.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Review of Intrusion Detection Defense Solutions Based on Software Defined Network

Most networks without fixed infrastructure are based on cloud computing face various challenges. In recent years, different methods have been used to distribute software defined network to address these challenges. This technology, while having many capabilities, faces some vulnerabilities in the face of some common threats and destructive factors such as distributed Denial of Service. A review...

متن کامل

Security Research for Software Defined Network

With the changing of network structure, software defined network becomes the main structure of the next generation network, which can realize network definition by the software programming according to the control platform, so that the network can be controlled. However, the network configuration is flexible and convenient, but also brings the problem of network security, so that the attacker c...

متن کامل

Language-Based Security for Software-Defined Networks

In many settings, including campuses, enterprises, militaries, and datacenters, networks must be shared between entities that send and receive traffic over common hardware. We analyze the fundamental problem of how to program shared networks in a secure and reliable manner. Our solution is based on a new programming model that supports the concept of a network slice. Slices isolate the traffic ...

متن کامل

Neural Network Based Protection of Software Defined Network Controller against Distributed Denial of Service Attacks

Software Defined Network (SDN) is a new architecture for network management and its main concept is centralizing network management in the network control level that has an overview of the network and determines the forwarding rules for switches and routers (the data level). Although this centralized control is the main advantage of SDN, it is also a single point of failure. If this main contro...

متن کامل

A Security Assessment Mechanism for Software-Defined Networking-Based Mobile Networks

Software-Defined Networking-based Mobile Networks (SDN-MNs) are considered the future of 5G mobile network architecture. With the evolving cyber-attack threat, security assessments need to be performed in the network management. Due to the distinctive features of SDN-MNs, such as their dynamic nature and complexity, traditional network security assessment methodologies cannot be applied directl...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Computer Science and Information Systems

سال: 2022

ISSN: ['1820-0214', '2406-1018']

DOI: https://doi.org/10.2298/csis210222001g