Back to Search Start Over

PSA: An Architecture for Proactively Securing Protocol-Oblivious SDN Networks

Authors :
Tong Liu
Haojie Tong
Lei Mei
Ye Tian
Source :
2019 IEEE 9th International Conference on Electronics Information and Emergency Communication (ICEIEC).
Publication Year :
2019
Publisher :
IEEE, 2019.

Abstract

Up to now, Software-defined network (SDN) has been developing for many years and various controller implementations have appeared. Most of these controllers contain the normal business logic as well as security defense function. This makes the business logic on the controller tightly coupled with the security function, which increases the burden of the controller and is not conducive to the evolution of the controller. To address this problem, we propose a proactive security framework PSA, which decouples the business logic and security function of the controller, and deploys the security function in the proactive security layer which lies between the data plane and the control plane, so as to provide a unified security defense framework for different controller implementations. Based on PSA, we design a security defense application for the data-to-control plane saturation attack, which overloads the infrastructure of SDN networks. We evaluate the prototype implementation of PSA in the software environments. The results show that PSA is effective with adding only minor overhead into the entire SDN infrastructure.

Details

Database :
OpenAIRE
Journal :
2019 IEEE 9th International Conference on Electronics Information and Emergency Communication (ICEIEC)
Accession number :
edsair.doi...........596a7bd321edd523638d2ce84a69391f
Full Text :
https://doi.org/10.1109/iceiec.2019.8784667