OFMTL-SEC: State-based Security for Software Defined Networks

Sandra Scott-Hayward, Thianantha Arumugam

Research output: Chapter in Book/Report/Conference proceedingConference contribution

8 Citations (Scopus)
479 Downloads (Pure)

Abstract

Dynamic network security services have been proposed exploiting the benefits of Software Defined Networking (SDN) and Network Functions Virtualization (NFV) technologies. However, many of these services rely on controller interaction, which presents a performance and scalability challenge, and a threat vector. To overcome the performance issue, stateful data-plane designs have been proposed. Unfortunately, these solutions do not offer protection from attacks that exploit the SDN implementation of network functions such as topology and path update, or services such as the Address Resolution Protocol (ARP). In this work, we propose state-based SDN security protection mechanisms. Our stateful security data plane solution, OFMTL-SEC, is designed to provide protection against attacks on SDN and traditional network services. Specifically, we present a novel data plane protection against configuration-based attacks in SDN and against ARP spoofing. OFMTL-SEC is compared with the state-of-the-art solutions and offers increased security to SDNs with negligible performance impact.
Original languageEnglish
Title of host publication2018 IEEE Conference on Network Function Virtualization and Software Defined Networks
PublisherInstitute of Electrical and Electronics Engineers Inc.
Number of pages7
ISBN (Electronic)978-1-5386-8281-4
ISBN (Print)978-1-5386-8282-1
DOIs
Publication statusPublished - 30 May 2019
Event2018 IEEE Conference on Network Function Virtualization and Software Defined Networks - Verona, Italy
Duration: 27 Nov 201829 Nov 2018

Conference

Conference2018 IEEE Conference on Network Function Virtualization and Software Defined Networks
Country/TerritoryItaly
CityVerona
Period27/11/201829/11/2018

Fingerprint

Dive into the research topics of 'OFMTL-SEC: State-based Security for Software Defined Networks'. Together they form a unique fingerprint.

Cite this