• DocumentCode
    2738937
  • Title

    Trust support for SDN controllers and virtualized network applications

  • Author

    Betge-Brezetz, Stephane ; Kamga, Guy-Bertrand ; Tazi, Monsef

  • Author_Institution
    Alcatel-Lucent Bell Labs., Nozay, France
  • fYear
    2015
  • fDate
    13-17 April 2015
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    The SDN paradigm allows networks to be dynamically reconfigurable by network applications. SDN is also of particular interest for NFV which deals with the virtualization of network functions. The network programmability offered by SDN presents then various advantages but it also induces various threats regarding potential attacks on the network. For instance, there is a critical risk that a hacker takes over the network control by exploiting this SDN network programmability (e.g., using the SDN API or tampering a network application running on the SDN controller). This paper proposes then an approach to deal with this possible lack of trust in the SDN controller or in their applications. This approach consists in not relying on a single controller but on several `redundant´ controllers that may also run in different execution environments. The network configuration requests coming from these controllers are then compared and, if deemed sufficiently consistent and then trustable, they are actually sent to the network. This approach has been implemented in an intermediary layer (based on a network hypervisor) inserted between the network equipments and the controllers. Experimentations have been performed showing the feasibility of the approach and providing some first evaluations of its impact on the network and the services.
  • Keywords
    application program interfaces; computer network security; software defined networking; trusted computing; virtualisation; NFV; SDN API; SDN controllers; SDN network programmability; SDN paradigm; network configuration requests; network control; network equipments; network function virtualization; network hypervisor; network programmability; redundant controllers; trust support; virtualized network applications; Computer architecture; Network topology; Prototypes; Routing; Security; Virtual machine monitors; Virtualization; NFV; SDN; network applications; network hypervisor; network virtualization; security; trust;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Softwarization (NetSoft), 2015 1st IEEE Conference on
  • Conference_Location
    London
  • Type

    conf

  • DOI
    10.1109/NETSOFT.2015.7116153
  • Filename
    7116153