Control-plane isolation and recovery for a secure SDN architecture

Control-plane isolation and recovery for a secure SDN architecture
复制标题

安全 SDN 架构的控制平面隔离和恢复

DOI:
10.1109/netsoft.2016.7502485
复制
发表时间:
2016
期刊:
IEEE Conference on Network Softwarization
影响因子:
--
通讯作者:
D. E. Asoni
D. E. Asoni
中科院分区:
--
文献类型:
--
作者:
Takayuki Sasaki;A. Perrig;D. E. Asoni

文献摘要

被引文献

相似文献

软件定义网络(SDN)支持可扩展且灵活的网络管理,无需更换昂贵的硬件。然而,这项技术相对较新,并带来了新的安全风险。更具体地说,在当前的SDN设计中,(1)由于其集中式架构,受损组件可能会影响整个SDN网络,以及(2)现有设计不允许恢复受损组件。为了解决这些问题,我们提出了一种安全的SDN体系结构,该体系结构(1)通过使用强大的软件隔离机制来限制受攻击的控制器和交换进程造成的损害,以及(2)通过定期地自动地将受攻击的控制器和交换进程回滚到原始状态来允许恢复受攻击的控制器和交换进程。我们展示了这些机构的详细设计。我们讨论了系统设计的主要方面,并给出了一个原型实现的初步评估结果。
Software Defined Networking (SDN) allows scalable and flexible network management without requiring costly hardware changes. However, this technology is relatively new, and creates new security risks. More specifically, in current SDN designs (1) a compromised component can affect the whole SDN network due to its centralized architecture, and (2) existing designs do not allow recovery of compromised components. To solve these problems, we propose a secure SDN architecture which (1) limits damage due to a compromised controller and switch processes by using strong software isolation mechanisms, and (2) allows recovery of compromised controller and switch processes by regularly and automatically rolling them back to a pristine state. We show detailed designs of these mechanisms. We discuss the main aspects of our system's design and show preliminary evaluation results of a prototype implementation.