A Comprehensive Security Analysis Checksheet for OpenFlow Networks

A Comprehensive Security Analysis Checksheet for OpenFlow Networks
复制标题

OpenFlow 网络的综合安全分析检查表

DOI:
10.1007/978-3-319-49106-6_22
复制
发表时间:
2017
期刊:
Proc. of BWCCA2016, Lecture Notes on Data Engineering and Communications Technologies(LNDECT), Springer
影响因子:
--
通讯作者:
Kouichi Sakurai
Kouichi Sakurai
中科院分区:
--
文献类型:
--
作者:
Yoshiaki Hori;Seiichiro Mizoguchi;Ryosuke Miyazaki;Akira Yamada;Yaokai Feng;Ayumu Kubota;Kouichi Sakurai

文献摘要

相似文献

软件定义网络(SDN)实现了网络的灵活和动态配置,而OpenFlow是一种实际的SDN实现。虽然它已广泛部署在实际环境中,但它可能会导致致命的AWS。在本文中,我们巩固了以前工作中提到的对OpenFlow的安全威胁,并引入了一种新的安全检查表,其中包括风险评估方法。我们比较了Kreutz等人。使用SDNSecurity.org攻击列表来发现新的威胁。我们的检查表可以对给定OpenFlow网络设计的安全性进行全面评估。此外,我们使用检查表评估了具有两种攻击场景的OpenFlow网络的性能,并确定了严重的性能降级。
Software-defined networking (SDN) enables the exible and dynamic configuration of a network, and OpenFlow is one practical SDN implementation. Although it has been widely deployed in actual environments, it can cause fatal aws. In this paper, we consolidate the security threats to OpenFlow mentioned in previous work and introduce a new security checksheet that includes risk assessment methods. We compare the Kreutz et al. threat vectors with the SDNSecurity.org attack list to discover new threats. Our checksheet enables the security of a given OpenFlow network design to be comprehensively assessed. Furthermore, we evaluate the performance of an OpenFlow network with two attack scenarios using the checksheet and identify critical performance degradations.