Virtualized network views for localizing misbehaving sources in SDN data planes

Virtualized network views for localizing misbehaving sources in SDN data planes
复制标题

用于定位 SDN 数据平面中行为不当源的虚拟化网络视图

DOI:
10.1109/icc.2017.7997296
复制
发表时间:
2017
期刊:
2017 IEEE International Conference on Communications (ICC)
影响因子:
--
通讯作者:
A. Chehab
A. Chehab
中科院分区:
--
文献类型:
--
作者:
Maha Shamseddine;W. Itani;A. Kayssi;A. Chehab

文献摘要

被引文献

相似文献

在本文中,我们提出了VISKA,一个云安全服务,用于检测软件定义网络(SDN)环境中的恶意交换元素。VISKA利用网络虚拟化和安全概率草图来隔离底层SDN网络数据平面中的行为不当的交换机。主要贡献在于利用SDN环境中的网络虚拟化来动态隔离数据平面的部分并检查其转发行为。这是通过在映射到这些数据平面分区的虚拟化网络视图上应用一组集中的分组探测和绘制机制来实现的,而不是将安全机制集中在整个物理网络上。VISKA灵活地分析粒度虚拟视图的网络行为,并递归地划分这些视图,以减少问题的大小,以定位异常/恶意的网络交换单元。在OpenVirtex SDN网络虚拟化平台上实现了测试床原型实现。实验分析证实了该算法的收敛性能,使用线性和FatTree拓扑结构与SDN网络规模高达250个交换单元。
In this paper, we present VISKA, a Cloud security service for detecting malicious switching elements in software defined networking (SDN) environments. VISKA leverages network virtualization and secure probabilistic sketching to isolate misbehaving switches in the underlying SDN network data plane. The main contribution lies in utilizing network virtualization in SDN environments to dynamically isolate parts of the data plane and check their forwarding behavior. This is achieved by applying a set of focused packet probing and sketching mechanisms on virtualized network views mapped to these data plane partitions instead of focusing the security mechanisms on the whole physical network. VISKA flexibly analyzes the network behavior of the granular virtual views and recursively partitions these views to reduce the problem size in order to localize abnormal/malicious network switching units. A test bed prototype implementation is realized on the OpenVirtex SDN network virtualization platform. The experimental analysis corroborated the algorithm's convergence property using the linear and FatTree topologies with SDN network sizes of up to 250 switching units.