Virtualized network views for localizing misbehaving sources in SDN data planes
Virtualized network views for localizing misbehaving sources in SDN data planes
复制标题
用于定位 SDN 数据平面中行为不当源的虚拟化网络视图
DOI:
10.1109/icc.2017.7997296
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
A. Chehab
中科院分区:
文献类型:
--
作者:
Maha Shamseddine;W. Itani;A. Kayssi;A. Chehab
In this paper, we present VISKA, a Cloud security service for detecting malicious switching elements in software defined networking (SDN) environments. VISKA leverages network virtualization and secure probabilistic sketching to isolate misbehaving switches in the underlying SDN network data plane. The main contribution lies in utilizing network virtualization in SDN environments to dynamically isolate parts of the data plane and check their forwarding behavior. This is achieved by applying a set of focused packet probing and sketching mechanisms on virtualized network views mapped to these data plane partitions instead of focusing the security mechanisms on the whole physical network. VISKA flexibly analyzes the network behavior of the granular virtual views and recursively partitions these views to reduce the problem size in order to localize abnormal/malicious network switching units. A test bed prototype implementation is realized on the OpenVirtex SDN network virtualization platform. The experimental analysis corroborated the algorithm's convergence property using the linear and FatTree topologies with SDN network sizes of up to 250 switching units.