• DocumentCode
    160102
  • Title

    OrchSec: An orchestrator-based architecture for enhancing network-security using Network Monitoring and SDN Control functions

  • Author

    Zaalouk, Adel ; Khondoker, Rahamatullah ; Marx, Ronald ; Bayarou, Kpatcha

  • Author_Institution
    RWTH Aachen Univ., Aachen, Germany
  • fYear
    2014
  • fDate
    5-9 May 2014
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    The original design of the Internet did not take network security aspects into consideration, instead it aimed to facilitate the process of information exchange between end-hosts. Consequently, many protocols that are part of the Internet infrastructure expose a set of vulnerabilities that can be exploited by attackers. To reduce these vulnerabilities, several security approaches were introduced as a form of add-ons to the existing Internet architecture. However, these approaches have their drawbacks (e.g., lack of centralized control, and automation). In this paper, to address these drawbacks, the features provided by Software Defined Networking (SDN) such as network-visibility, centralized management and control are considered for developing security applications. Although the SDN architecture provides features that can aid in the process of network security, it has some deficiencies when it comes to using SDN for security. To address these deficiencies, several architectural requirements are derived to adapt the SDN architecture for security use cases. For this purpose, OrchSec, an Orchestrator-based architecture that utilizes Network Monitoring and SDN Control functions to develop security applications is proposed. The functionality of the proposed architecture is demonstrated, tested, and validated using a security application.
  • Keywords
    Internet; computer network security; Internet architecture; Internet infrastructure; OrchSec; SDN control functions; centralized control; network monitoring; network security aspects; network security enhancement; orchestrator based architecture; software defined networking; Monitoring; Prototypes; Switches;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium (NOMS), 2014 IEEE
  • Conference_Location
    Krakow
  • Type

    conf

  • DOI
    10.1109/NOMS.2014.6838409
  • Filename
    6838409