Securing data planes in software-defined networks
Securing data planes in software-defined networks
复制标题
DOI:
10.1109/netsoft.2016.7502486
复制
发表时间:
2016-06
期刊:
影响因子:
--
通讯作者:
Tzu-Wei Chao;Yu-Ming Ke;Bo-Han Chen;Jhu-Lin Chen;Chen Jung Hsieh;Shao-Chuan Lee;H. Hsiao
中科院分区:
文献类型:
--
作者:
Tzu-Wei Chao;Yu-Ming Ke;Bo-Han Chen;Jhu-Lin Chen;Chen Jung Hsieh;Shao-Chuan Lee;H. Hsiao
Ensuring correct data-plane operations is an integral part of securing software-defined networks (SDN). This paper explores practical solutions for localizing and mitigating malicious switches that disobey installed flow rules. Our main insight is that the flexible and proactive nature of SDNs enables efficient defense against realistic adversaries who can collude and report falsified information in addition to manipulating packet forwarding decisions. In contrast, previous proposals either assume a simple threat model or require expensive cryptographic operations even during peacetime. To systematically explore the design space, we study three complementary techniques for data-plane security, that is, active probing, statistics checking, and packet obfuscation. This paper presents the initial design and implementation of our data-plane security system and highlight potential research challenges.