B-DAC: A Decentralized Access Control Framework on Northbound Interface for Securing SDN Using Blockchain

11/01/2021
by   Phan The Duy, et al.
0

Software-Defined Network (SDN) is a new arising terminology of network architecture with outstanding features of orchestration by decoupling the control plane and the data plane in each network element. Even though it brings several benefits, SDN is vulnerable to a diversity of attacks. Abusing the single point of failure in the SDN controller component, hackers can shut down all network operations. More specifics, a malicious OpenFlow application can access to SDN controller to carry out harmful actions without any limitation owing to the lack of the access control mechanism as a standard in the Northbound. The sensitive information about the whole network such as network topology, flow information, and statistics can be gathered and leaked out. Even worse, the entire network can be taken over by the compromised controller. Hence, it is vital to build a scheme of access control for SDN's Northbound. Furthermore, it must also protect the data integrity and availability during data exchange between application and controller. To address such limitations, we introduce B-DAC, a blockchain-based framework for decentralized authentication and fine-grained access control for the Northbound interface to assist administrators in managing and protecting critical resources. With strict policy enforcement, B-DAC can perform decentralized access control for each request to keep network applications under surveillance for preventing over-privileged activities or security policy conflicts. To demonstrate the feasibility of our approach, we also implement a prototype of this framework to evaluate the security impact, effectiveness, and performance through typical use cases.

READ FULL TEXT

page 1

page 7

page 17

page 22

research
06/11/2019

Secure Software-Defined Networking Based on Blockchain

Software-Defined Networking (SDN) separates the network control plane an...
research
11/20/2018

SDN Access Control for the Masses

The evolution of Software-Defined Networking (SDN) has so far been predo...
research
07/07/2018

Gargoyle: A Network-based Insider Attack Resilient Framework for Organizations

`Anytime, Anywhere' data access model has become a widespread IT policy ...
research
01/05/2022

Benchmarking the ONOS Intent interfaces to ease 5G service management

The use cases of the upcoming 5G mobile networks introduce new and compl...
research
05/27/2021

SDN-based Runtime Security Enforcement Approach for Privacy Preservation of Dynamic Web Service Composition

Aiming at the privacy preservation of dynamic Web service composition, t...
research
09/01/2016

Suspicious-Taint-Based Access Control for Protecting OS from Network Attacks

Today, security threats to operating systems largely come from network. ...
research
06/25/2020

Blockchain-Aided Flow Insertion and Verification in Software Defined Networks

The Internet of Things (IoT) connected by Software Defined Networking (S...

Please sign up or login with your details

Forgot password? Click here to reset