ANCHOR

ANCHOR
复制标题

锚

DOI:
--
复制
发表时间:
2017
影响因子:
2.3
通讯作者:
Paulo Esteves
Paulo Esteves
中科院分区:
计算机科学4区
文献类型:
--
作者:
D. Kreutz;Jiangshan Yu;Fernando M. V. Ramos;Paulo Esteves

文献摘要

被引文献

相似文献

软件定义网络(SDN)将传统网络的控制和数据平面进行了扩展,在逻辑上将网络的功能属性集中在SDN控制器中。虽然这种集中化带来了更快的创新速度等优势,但它也破坏了传统架构对不同威胁的一些自然防御。关于SDN的文献大多关注功能方面,尽管有一些关于非功能属性(如安全性或可靠性)的具体工作。虽然以临时、零敲碎打的方式处理后者可能会奏效,但这很可能导致效率和效力问题。我们认为,作为SDN鲁棒性的支柱,非功能属性的实施需要一种系统性的方法。我们进一步主张,为了实现它,重申SDN背后的成功公式:“逻辑集中化”。作为一个一般的概念,我们提出了锚,一个子系统架构,促进非功能属性的逻辑集中。为了展示这一概念的有效性,我们在本文中重点关注安全性:我们确定了SDN中当前的安全漏洞,并以全局和一致的方式使用适当的安全机制填充架构中间件。锚提供的基本安全机制包括可靠的熵和弹性伪随机生成器,以及用于SDN设备的安全注册和关联的协议。我们在文章中声称并证明,集中这些机制是其有效性的关键,允许我们为这些属性定义和执行全局策略;降低控制器和转发设备的复杂性;确保关键服务的更高级别的鲁棒性;促进非功能性属性执行机制的互操作性;并促进架构本身的安全性和弹性。我们讨论的设计和实现方面,我们证明和评估我们的算法和机制,包括形式化的主要协议和验证其核心的安全属性使用的Tamarin证明。
Software-defined networking (SDN) decouples the control and data planes of traditional networks, logically centralizing the functional properties of the network in the SDN controller. While this centralization brought advantages such as a faster pace of innovation, it also disrupted some of the natural defenses of traditional architectures against different threats. The literature on SDN has mostly been concerned with the functional side, despite some specific works concerning non-functional properties such as security or dependability. Though addressing the latter in an ad-hoc, piecemeal way may work, it will most likely lead to efficiency and effectiveness problems. We claim that the enforcement of non-functional properties as a pillar of SDN robustness calls for a systemic approach. We further advocate, for its materialization, the reiteration of the successful formula behind SDN: ‘logical centralization’. As a general concept, we propose anchor, a subsystem architecture that promotes the logical centralization of non-functional properties. To show the effectiveness of the concept, we focus on security in this article: we identify the current security gaps in SDNs and we populate the architecture middleware with the appropriate security mechanisms in a global and consistent manner. Essential security mechanisms provided by anchor include reliable entropy and resilient pseudo-random generators, and protocols for secure registration and association of SDN devices. We claim and justify in the article that centralizing such mechanisms is key for their effectiveness by allowing us to define and enforce global policies for those properties; reduce the complexity of controllers and forwarding devices; ensure higher levels of robustness for critical services; foster interoperability of the non-functional property enforcement mechanisms; and promote the security and resilience of the architecture itself. We discuss design and implementation aspects, and we prove and evaluate our algorithms and mechanisms, including the formalisation of the main protocols and the verification of their core security properties using the Tamarin prover.