SD-WAN Threat Landscape

11/12/2018
by   Sergey Gordeychik, et al.
0

Software Defined Wide Area Network (SD-WAN or SDWAN) is a modern conception and an attractive trend in network technologies. SD-WAN is defined as a specific application of software-defined networking (SDN) to WAN connections. There is growing recognition that SDN and SD-WAN technologies not only expand features, but also expose new vulnerabilities. Unfortunately, at the present time, most vendors say that SD-WAN are perfectly safe, hardened, and fully protected. The goal of this paper is to understand SD-WAN threats using practical approach. We describe basic SD-WAN features and components, investigate an attack surface, explore various vendor features and their security, explain threats and vulnerabilities found in SD-WAN products. We also extend existing SDN threat models by describing new potential threats and attack vectors, provide examples, and consider high-level approaches for their mitigations. The provided results may be used by SD-WAN developers as a part of Secure Software Development Life Cycle (SSDLC), security researchers for penetration testing and vulnerability assessment, system integrators for secure design of SD-WAN solutions, and finally customers for secure deployment operations and configurations of SD-WAN enabled network. The main idea of this work is that SD-WAN threat model involves all traditional network and SDN threats, as well as new product-specific threats, appended by vendors which reinvent or introduce proprietary technologies immature from a security perspective.

READ FULL TEXT

page 8

page 12

page 16

page 20

research
04/08/2018

The Challenges in SDN/ML Based Network Security : A Survey

Machine Learning is gaining popularity in the network security domain as...
research
07/16/2020

A Framework for Threats Analysis Using Software-Defined Networking

The ability to analyze network threats is very important in security res...
research
11/22/2021

Threat Modeling and Security Analysis of Containers: A Survey

Traditionally, applications that are used in large and small enterprises...
research
06/27/2020

Domain Name System Security and Privacy: A Contemporary Survey

The domain name system (DNS) is one of the most important components of ...
research
06/23/2018

A Recursive PLS (Partial Least Squares) based Approach for Enterprise Threat Management

Most of the existing solutions to enterprise threat management are preve...
research
06/23/2019

Experimental Security Analysis of Controller Software in SDNs: A Review

The software defined networking paradigm relies on the programmability o...
research
01/13/2023

Threat Models over Space and Time: A Case Study of E2EE Messaging Applications

Threat modelling is foundational to secure systems engineering and shoul...

Please sign up or login with your details

Forgot password? Click here to reset