• DocumentCode
    703012
  • Title

    Retaining control over SDN network services

  • Author

    Ropke, Christian ; Holz, Thorsten

  • Author_Institution
    Ruhr-Univ. Bochum, Bochum, Germany
  • fYear
    2015
  • fDate
    9-12 March 2015
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Both academic researchers and network vendors have started to promote Software-Defined Networking (SDN) as a new network paradigm, in which controller systems play a major role. A modular and extensible design allows network operators to extend the controller´s functionality by so called network services. Unfortunately, in current designs such network services have unlimited access to mandatory SDN resources which enables different kinds of attacks. To retain control over network services (especially third-party ones), we adapt approved security mechanisms and propose a containment mechanism as well as a framework to ease containment configuration. For both proposals, we provide proof-of-concept implementations for an open and industry-supported reference framework and hereby aim to improve security for a wide range of SDN controllers. Finally, our proposals achieve the ability to harden a mandatory SDN component (i. e., the SDN controller) and enable proactive security even against malicious network services.
  • Keywords
    computer network security; software defined networking; SDN controllers; SDN network service; industry-supported reference framework; malicious network service; network vendor; retaining control; security mechanism; software-defined networking; Access control; Conferences; Java; Software; Switches;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networked Systems (NetSys), 2015 International Conference and Workshops on
  • Conference_Location
    Cottbus
  • Type

    conf

  • DOI
    10.1109/NetSys.2015.7089082
  • Filename
    7089082