Strengthening SDN Security: Protocol Dialecting and Downgrade Attacks

10/22/2020
by   Michael Sjoholmsierchio, et al.
0

Software-defined networking (SDN) has become a fundamental technology for data centers and 5G networks. In an SDN network, routing and traffic management decisions are made by a centralized controller and communicated to switches via a control channel. Transport Layer Security (TLS) has been proposed as its single security layer; however, use of TLS is optional and connections are still vulnerable to downgrade attacks. In this paper, we propose the strengthening of security assurance using a protocol dialecting approach to provide additional and customizable security. We consider and evaluate two dialecting approaches for OpenFlow protocol operation, adding per-message authentication to the SDN control channel that is independent of TLS and provides robustness against downgrade attacks in the optional case of TLS implementation. Furthermore, we measure the performance impact of using these dialecting primitives in a Mininet experiment. The results show a modest increase of communication latency of less than 22

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/27/2020

Software Enabled Security Architecture for Counteracting Attacks in Control Systems

Increasingly Industrial Control Systems (ICS) systems are being connecte...
research
07/18/2021

QuicSDN: Transitioning from TCP to QUIC for Southbound Communication in SDNs

Transport and security layer protocols make up the backbone of communica...
research
06/08/2018

A SDN-based Flexible System for On-the-Fly Monitoring and Treatment of Security Events

The Software Defined Networking (SDN) paradigm decouples control and dat...
research
02/14/2023

SDN-AAA: Towards the standard management of AAA infrastructures

Software Defined Networking (SDN) is a widely deployed technology enabli...
research
12/27/2019

Detecting DDoS Attack on SDN Due to Vulnerabilities in OpenFlow

Software Defined Networking (SDN) is a network paradigm shift that facil...
research
11/02/2019

SDN Enhanced Ethernet VPN for Data Center Interconnect

Ethernet Virtual Private Network (EVPN) is an emerging technology that a...
research
07/08/2019

P4-IPsec: Implementation of IPsec Gateways in P4 with SDN Control for Host-to-Site Scenarios

In this paper we propose P4-IPsec which follows the software-defined net...

Please sign up or login with your details

Forgot password? Click here to reset