SDNShield: Reconciliating Configurable Application Permissions for SDN App Markets

SDNShield: Reconciliating Configurable Application Permissions for SDN App Markets
复制标题

DOI:
10.1109/dsn.2016.20
复制
发表时间:
2016-06
期刊:
2016 46th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Xitao Wen;Bo Yang;Yan Chen;Chengchen Hu;Yi Wang;B. Liu;Xiaolin Chen
Xitao Wen;Bo Yang;Yan Chen;Chengchen Hu;Yi Wang;B. Liu;Xiaolin Chen
中科院分区:
其他
文献类型:
--
作者:
Xitao Wen;Bo Yang;Yan Chen;Chengchen Hu;Yi Wang;B. Liu;Xiaolin Chen

文献摘要

被引文献

相似文献

OpenFlow范式涵盖了第三方开发工作,因此遭受了潜在的攻击,这些攻击篡夺了控制平面应用程序(APPS)的过度特权。这种特权滥用可能导致各种攻击影响整个行政领域。在本文中,我们提出了SDNShield,这是一个权限控制系统,可帮助网络管理员表达和强制对单个控制器应用程序的最低要求的特权。 SDNShield通过(i)精细的SDN许可摘要实现了这一目标,该摘要允许准确表示应用程序行为边界,(ii)将管理员指定的安全策略的自动安全策略对帐,并将管理员指定的安全策略纳入请求的APP权限中,以及(iii)轻型线程 - 用于控制器/应用程序隔离和可靠许可执行的基于基于控制器的控制器体系结构。通过原型实施,我们验证了其针对概念验证攻击的有效性。绩效评估表明,SDNShield引入了可忽略的运行时开销。
The OpenFlow paradigm embraces third-party development efforts, and therefore suffers from potential attacks that usurp the excessive privileges of control plane applications (apps). Such privilege abuse could lead to various attacks impacting the entire administrative domain. In this paper, we present SDNShield, a permission control system that helps network administrators to express and enforce only the minimum required privileges to individual controller apps. SDNShield achieves this goal through (i) fine-grained SDN permission abstractions that allow accurate representation of app behavior boundary, (ii) automatic security policy reconciliation that incorporates security policies specified by administrators into the requested app permissions, and (iii) a lightweight thread-based controller architecture for controller/app isolation and reliable permission enforcement. Through prototype implementation, we verify its effectiveness against proof-of-concept attacks. Performance evaluation shows that SDNShield introduces negligible runtime overhead.