SENSS: Software Defined Security Service
نویسندگان
چکیده
Network attacks have long been an important problem, and have attracted a lot of research in academic and commercial sector. With a rapidly growing number of critical as well as business applications deployed on the Internet today, network attacks have both become more lucrative for the attackers and more damaging to the victims. The implications of network attacks on the victim can be huge. For example a distributed denial-of-service (DDoS) can overwhelm the victim and make it unable to handle its regular business. A large-volume DDoS attack can further cause collateral damage to traffic that shares links with the victim’s traffic, leading to large traffic drops, BGP session interruptions and routing interruptions [6]. Besides the data plane attacks, control plane misconfigurations and attacks on the interdomain routing protocol BGP [5] can have dire implications for victim networks. For example, the prefix-hijacking attack injects and propagates false routes to the Internet, causing victim’s traffic to be redirected to the attacker networks for sniffing, modification or dropping [1]. Traffic sniffing and modification are very difficult to detect and mitigate, and create huge security and privacy issues for the victim, while blackholing severely affects online businesses and critical infrastructures. Many solutions have been proposed to detect and mitigate individual attacks. For example, in DDoS realm many victim-deployed or ISP-deployed DDoS defenses, overlay-based DDoS defenses [3] and content replication to sustain high-volume attacks have been proposed and deployed. In routing realm, detection approaches that monitor live BGP data feeds and conduct data plane probing have been proposed to diagnose prefix-hijacking attacks. But ultimately, traffic flows, attacks, and their routes are the results of actions of multiple networks, each following its individual interests and priorities. Thus, while many attack instances can be handled by the victim and its local ISP, there will always exist attacks that cannot be diagnosed or mitigated without help from remote networks, which are involved in sourcing or carrying traffic to the victim. Today’s Internet lacks such wide-scale, general service for automated inter-ISP collaboration on security problem diagnosis and mitigation. There have been numerous research works on inter-ISP collaboration for attack diagnosis and mitigation, such as collaborative DDoS defenses, collaborative worm defenses, and collaborative routing defenses. However, most proposals are still not deployed today because: (1) Most of the proposals only focus on detection or mitigation of one attack type or variant; (2) Some solutions require complex changes of the data plane or new router functionality, which are difficult to achieve; (3) Some solutions do not create proper incentives for ISPs to collaborate with each other.
منابع مشابه
Security of Software Defined Networks: A survey
Software Defined Networking (SDN) has emerged as a new network architecture for dealing with network dynamics through software-enabled control. While SDN is promoting many new network applications, security has become an important concern. This paper provides an extensive survey on SDN security. We discuss the security threats to SDN according to their effects, i.e., Spoofing, Tampering, Repudi...
متن کاملSoftware as a Service: Analyzing Security Issues
Software-as-a-service (SaaS) is a type of software service delivery model which encompasses a broad range of business opportunities and challenges. Users and service providers are reluctant to integrate their business into SaaS due to its security concerns while at the same time they are attracted by its benefits. This article highlights SaaS utility and applicability in different environments ...
متن کاملDynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
For a Software Defined Network (SDN), security is an important factor affecting its large-scale deployment. The existing security solutions for SDN mainly focus on the controller itself, which has to handle all the security protection tasks by using the programmability of the network. This will undoubtedly involve a heavy burden for the controller. More devastatingly, once the controller itself...
متن کاملSurvey the Security Function of Integration of vehicular ad hoc Networks with Software-defiend Networks
In recent years, Vehicular Ad Hoc Networks (VANETs) have emerged as one of the most active areas in the field of technology to provide a wide range of services, including road safety, passenger's safety, amusement facilities for passengers and emergency facilities. Due to the lack of flexibility, complexity and high dynamic network topology, the development and management of current Vehicular A...
متن کاملSoftware Defined Security Service Provisioning Framework for Internet of Things
Programmable management framework have paved the way for managing devices in the network. Lately, emerging paradigm of Software Defined Networking (SDN) have revolutionized programmable networks. Designers of networking applications i.e. Internet of things (IoT) have started investigating potentials of SDN paradigm in improving network management. IoT envision interconnecting various embedded d...
متن کاملSecured Structural Design for Software Defined Data Center Networks
Research work provides efficient security which protects network resources from internal and external threats. Network virtualization is used to provide users with well-organized, controlled, and safe sharing of the networking resources. It also ensures privacy of data and integrity in Software-defined data center (SDDC) whose infrastructures is virtualized and distributed as a service. SDDC he...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2014