Strengthening SDN Security: Protocol Dialecting and Downgrade Attacks

by   Michael Sjoholmsierchio, et al.

Software-defined networking (SDN) has become a fundamental technology for data centers and 5G networks. In an SDN network, routing and traffic management decisions are made by a centralized controller and communicated to switches via a control channel. Transport Layer Security (TLS) has been proposed as its single security layer; however, use of TLS is optional and connections are still vulnerable to downgrade attacks. In this paper, we propose the strengthening of security assurance using a protocol dialecting approach to provide additional and customizable security. We consider and evaluate two dialecting approaches for OpenFlow protocol operation, adding per-message authentication to the SDN control channel that is independent of TLS and provides robustness against downgrade attacks in the optional case of TLS implementation. Furthermore, we measure the performance impact of using these dialecting primitives in a Mininet experiment. The results show a modest increase of communication latency of less than 22



There are no comments yet.


page 1

page 2

page 3

page 4


Software Enabled Security Architecture for Counteracting Attacks in Control Systems

Increasingly Industrial Control Systems (ICS) systems are being connecte...

QuicSDN: Transitioning from TCP to QUIC for Southbound Communication in SDNs

Transport and security layer protocols make up the backbone of communica...

A SDN-based Flexible System for On-the-Fly Monitoring and Treatment of Security Events

The Software Defined Networking (SDN) paradigm decouples control and dat...

Detecting DDoS Attack on SDN Due to Vulnerabilities in OpenFlow

Software Defined Networking (SDN) is a network paradigm shift that facil...

A Software-Defined Networking approach for congestion control in Opportunistic Networking

The short-term adoption of opportunistic networks (OppNet) depends on im...

SDN Enhanced Ethernet VPN for Data Center Interconnect

Ethernet Virtual Private Network (EVPN) is an emerging technology that a...

Fast, Reliable, and Secure Drone Communication: A Comprehensive Survey

Drone security is currently a major topic of discussion among researcher...
This week in AI

Get the week's most popular data science and artificial intelligence research sent straight to your inbox every Saturday.