ANCHOR

Author:

Kreutz Diego1ORCID,Yu Jiangshan2ORCID,Ramos Fernando M. V.3,Esteves-Verissimo Paulo4

Affiliation:

1. SnT, University of Luxembourg and Federal University of Pampa, avenue de la Fonte, Esch-sur-AlzetteBrazil, Brazil

2. SnT, University of Luxembourg and Monash University, Clayton VIC, Australia

3. LASIGE, Faculdade de Ciências, Universidade de Lisboa, Lisboa, Portugal

4. SnT, University of Luxembourg, Luxembourg, avenue de la Fonte, Esch-sur-Alzette

Abstract

Software-defined networking (SDN) decouples the control and data planes of traditional networks, logically centralizing the functional properties of the network in the SDN controller. While this centralization brought advantages such as a faster pace of innovation, it also disrupted some of the natural defenses of traditional architectures against different threats. The literature on SDN has mostly been concerned with the functional side, despite some specific works concerning non-functional properties such as security or dependability. Though addressing the latter in an ad-hoc, piecemeal way may work, it will most likely lead to efficiency and effectiveness problems. We claim that the enforcement of non-functional properties as a pillar of SDN robustness calls for a systemic approach. We further advocate, for its materialization, the reiteration of the successful formula behind SDN: ‘logical centralization’. As a general concept, we propose anchor , a subsystem architecture that promotes the logical centralization of non-functional properties. To show the effectiveness of the concept, we focus on security in this article: we identify the current security gaps in SDNs and we populate the architecture middleware with the appropriate security mechanisms in a global and consistent manner. Essential security mechanisms provided by anchor include reliable entropy and resilient pseudo-random generators, and protocols for secure registration and association of SDN devices. We claim and justify in the article that centralizing such mechanisms is key for their effectiveness by allowing us to define and enforce global policies for those properties; reduce the complexity of controllers and forwarding devices; ensure higher levels of robustness for critical services; foster interoperability of the non-functional property enforcement mechanisms; and promote the security and resilience of the architecture itself. We discuss design and implementation aspects, and we prove and evaluate our algorithms and mechanisms, including the formalisation of the main protocols and the verification of their core security properties using the T amarin prover.

Funder

European Commission

Fundação para a Ciência e a Tecnologia

Fonds National de la Recherche Luxembourg

Publisher

Association for Computing Machinery (ACM)

Subject

Safety, Risk, Reliability and Quality,General Computer Science

Cited by 9 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Skynet: a Cyber-Aware Intrusion Tolerant Overseer;2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks - Supplemental Volume (DSN-S);2023-06

2. Toward the Design of an Efficient and Secure System Based on the Software-Defined Network Paradigm for Vehicular Networks;IEEE Access;2023

3. Software-Defined Networking: Categories, Analysis, and Future Directions;Sensors;2022-07-25

4. Efficient and Secure Topology Discovery in SDN: Review;Advances on Intelligent Informatics and Computing;2022

5. Migrating From Legacy to Software Defined Networks: A Network Reliability Perspective;IEEE Transactions on Reliability;2021-12

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3