DocumentCode
703012
Title
Retaining control over SDN network services
Author
Ropke, Christian ; Holz, Thorsten
Author_Institution
Ruhr-Univ. Bochum, Bochum, Germany
fYear
2015
fDate
9-12 March 2015
Firstpage
1
Lastpage
5
Abstract
Both academic researchers and network vendors have started to promote Software-Defined Networking (SDN) as a new network paradigm, in which controller systems play a major role. A modular and extensible design allows network operators to extend the controller´s functionality by so called network services. Unfortunately, in current designs such network services have unlimited access to mandatory SDN resources which enables different kinds of attacks. To retain control over network services (especially third-party ones), we adapt approved security mechanisms and propose a containment mechanism as well as a framework to ease containment configuration. For both proposals, we provide proof-of-concept implementations for an open and industry-supported reference framework and hereby aim to improve security for a wide range of SDN controllers. Finally, our proposals achieve the ability to harden a mandatory SDN component (i. e., the SDN controller) and enable proactive security even against malicious network services.
Keywords
computer network security; software defined networking; SDN controllers; SDN network service; industry-supported reference framework; malicious network service; network vendor; retaining control; security mechanism; software-defined networking; Access control; Conferences; Java; Software; Switches;
fLanguage
English
Publisher
ieee
Conference_Titel
Networked Systems (NetSys), 2015 International Conference and Workshops on
Conference_Location
Cottbus
Type
conf
DOI
10.1109/NetSys.2015.7089082
Filename
7089082
Link To Document