DocumentCode :
160102
Title :
OrchSec: An orchestrator-based architecture for enhancing network-security using Network Monitoring and SDN Control functions
Author :
Zaalouk, Adel ; Khondoker, Rahamatullah ; Marx, Ronald ; Bayarou, Kpatcha
Author_Institution :
RWTH Aachen Univ., Aachen, Germany
fYear :
2014
fDate :
5-9 May 2014
Firstpage :
1
Lastpage :
9
Abstract :
The original design of the Internet did not take network security aspects into consideration, instead it aimed to facilitate the process of information exchange between end-hosts. Consequently, many protocols that are part of the Internet infrastructure expose a set of vulnerabilities that can be exploited by attackers. To reduce these vulnerabilities, several security approaches were introduced as a form of add-ons to the existing Internet architecture. However, these approaches have their drawbacks (e.g., lack of centralized control, and automation). In this paper, to address these drawbacks, the features provided by Software Defined Networking (SDN) such as network-visibility, centralized management and control are considered for developing security applications. Although the SDN architecture provides features that can aid in the process of network security, it has some deficiencies when it comes to using SDN for security. To address these deficiencies, several architectural requirements are derived to adapt the SDN architecture for security use cases. For this purpose, OrchSec, an Orchestrator-based architecture that utilizes Network Monitoring and SDN Control functions to develop security applications is proposed. The functionality of the proposed architecture is demonstrated, tested, and validated using a security application.
Keywords :
Internet; computer network security; Internet architecture; Internet infrastructure; OrchSec; SDN control functions; centralized control; network monitoring; network security aspects; network security enhancement; orchestrator based architecture; software defined networking; Monitoring; Prototypes; Switches;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Operations and Management Symposium (NOMS), 2014 IEEE
Conference_Location :
Krakow
Type :
conf
DOI :
10.1109/NOMS.2014.6838409
Filename :
6838409
Link To Document :
بازگشت