OpenFlow Security Threat Detection and Defense Services

نویسنده

  • Wanqing You
چکیده

OpenFlow Security Threat Detection and Defense Services Wanqing You Department of Computer Science, Southern Polytechnic State University, Georgia Email: [email protected] Kai Qian Department of Computer Science, Southern Polytechnic State University, Georgia Email: [email protected] Xi He Department of Computer Science, Georgia State University, Georgia Email: [email protected] Ying Qian Department of Computer Science, East China Normal University, China Email: [email protected] -------------------------------------------------------------------ABSTRACT-------------------------------------------------------------The emergence of OpenFlow-capable switches decouples control plane from the data flow plane so that they support programmable network and allow network administrators to have programmable central control of network traffic via a controller. The controller and its communication with switches and users become a malicious attack target. This paper explores major possible security threats and attacks on the controller of SDN and proposes a new approach to automatically and dynamically detect and monitor malicious behaviors on flow message passing and defend such attacks to ensure the security of SDN. We have built a FlowEye prototype at service level on Mininet API, and simulation tests are done on two feasible attacks on OpenFlow Beacon platform. The paper provides the feasibility study of such attacks and defense protection strategies in SDN security research.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

FRESCO: Modular Composable Security Services for Software-Defined Networks

OpenFlow is an open standard that has gained tremendous interest in the last few years within the network community. It is an embodiment of the software-defined networking paradigm, in which higher-level flow routing decisions are derived from a control layer that, unlike classic network switch implementations, is separated from the data handling layer. The central attraction to this paradigm i...

متن کامل

IntelFlow: Towards adding Cyber Threat Intelligence to Software Defined Networks

Security is a major concern in computer networking, which faces increasing threats as the commercial Internet and related economies continue to grow. Our work aims to explore advances in Cyber Threat Intelligence (CTI) in the context of Software Defined Networking (SDN). More specifically, we propose IntelFlow, an intelligence detection system for Software Defined Networking (SDN) that follows ...

متن کامل

A Comprehensive Security Analysis Checksheet for OpenFlow Networks

Software-defined networking (SDN) enables the flexible and dynamic configuration of a network, and OpenFlow is one practical SDN implementation. Although it has been widely deployed in actual environments, it can cause fatal flows. In this paper, we consolidate the security threats to OpenFlow mentioned in previous work and introduce a new security checksheet that includes risk assessment metho...

متن کامل

What you need to know about SDN control and data planes

SDN and OpenFlow are actively being standardized and deployed. These deployments rely on switches that come from various vendors and differ in terms of their performance and available features. Understanding these differences and basic performance characteristics is essential for ensuring efficient deployments. In this paper we measure, report, and explain the performance characteristics of the...

متن کامل

Towards Secured Firewalls for Software Defined Networks

Software-Defined Networking (SDN) offers programmers network-wide visibility and direct control over the underlying switches from a logically-centralized controller. SDN provides a promising way for the future development of Internet. SDN, however, also has some new security challenges. A critical challenge among them is how to build a reliable firewall application for SDN. Due to the stateless...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014