DocumentCode
160102
Title
OrchSec: An orchestrator-based architecture for enhancing network-security using Network Monitoring and SDN Control functions
Author
Zaalouk, Adel ; Khondoker, Rahamatullah ; Marx, Ronald ; Bayarou, Kpatcha
Author_Institution
RWTH Aachen Univ., Aachen, Germany
fYear
2014
fDate
5-9 May 2014
Firstpage
1
Lastpage
9
Abstract
The original design of the Internet did not take network security aspects into consideration, instead it aimed to facilitate the process of information exchange between end-hosts. Consequently, many protocols that are part of the Internet infrastructure expose a set of vulnerabilities that can be exploited by attackers. To reduce these vulnerabilities, several security approaches were introduced as a form of add-ons to the existing Internet architecture. However, these approaches have their drawbacks (e.g., lack of centralized control, and automation). In this paper, to address these drawbacks, the features provided by Software Defined Networking (SDN) such as network-visibility, centralized management and control are considered for developing security applications. Although the SDN architecture provides features that can aid in the process of network security, it has some deficiencies when it comes to using SDN for security. To address these deficiencies, several architectural requirements are derived to adapt the SDN architecture for security use cases. For this purpose, OrchSec, an Orchestrator-based architecture that utilizes Network Monitoring and SDN Control functions to develop security applications is proposed. The functionality of the proposed architecture is demonstrated, tested, and validated using a security application.
Keywords
Internet; computer network security; Internet architecture; Internet infrastructure; OrchSec; SDN control functions; centralized control; network monitoring; network security aspects; network security enhancement; orchestrator based architecture; software defined networking; Monitoring; Prototypes; Switches;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Operations and Management Symposium (NOMS), 2014 IEEE
Conference_Location
Krakow
Type
conf
DOI
10.1109/NOMS.2014.6838409
Filename
6838409
Link To Document