Securing data planes in software-defined networks

Securing data planes in software-defined networks
复制标题

DOI:
10.1109/netsoft.2016.7502486
复制
发表时间:
2016-06
期刊:
2016 IEEE NetSoft Conference and Workshops (NetSoft)
影响因子:
--
通讯作者:
Tzu-Wei Chao;Yu-Ming Ke;Bo-Han Chen;Jhu-Lin Chen;Chen Jung Hsieh;Shao-Chuan Lee;H. Hsiao
Tzu-Wei Chao;Yu-Ming Ke;Bo-Han Chen;Jhu-Lin Chen;Chen Jung Hsieh;Shao-Chuan Lee;H. Hsiao
中科院分区:
其他
文献类型:
--
作者:
Tzu-Wei Chao;Yu-Ming Ke;Bo-Han Chen;Jhu-Lin Chen;Chen Jung Hsieh;Shao-Chuan Lee;H. Hsiao

文献摘要

被引文献

相似文献

确保正确的数据平面操作是保护软件定义网络(SDN)的一个组成部分。本文探讨了实用的解决方案,本地化和减轻恶意交换机,不服从安装流规则。我们的主要观点是,SDN的灵活性和主动性使得能够有效地防御现实的对手,这些对手除了操纵数据包转发决策外,还可以串通和报告伪造的信息。相比之下,以前的提案要么假设一个简单的威胁模型,要么即使在和平时期也需要昂贵的加密操作。为了系统地探索设计空间,我们研究了数据平面安全的三种互补技术,即主动探测、统计检查和数据包混淆。本文介绍了我们的数据平面安全系统的初步设计和实现,并强调潜在的研究挑战。
Ensuring correct data-plane operations is an integral part of securing software-defined networks (SDN). This paper explores practical solutions for localizing and mitigating malicious switches that disobey installed flow rules. Our main insight is that the flexible and proactive nature of SDNs enables efficient defense against realistic adversaries who can collude and report falsified information in addition to manipulating packet forwarding decisions. In contrast, previous proposals either assume a simple threat model or require expensive cryptographic operations even during peacetime. To systematically explore the design space, we study three complementary techniques for data-plane security, that is, active probing, statistics checking, and packet obfuscation. This paper presents the initial design and implementation of our data-plane security system and highlight potential research challenges.