Van-Ca Nguyen, Anh-Vu Vu, Kyoungjae Sun, Younghan Kim
{"title":"An experimental study of security for service function chaining","authors":"Van-Ca Nguyen, Anh-Vu Vu, Kyoungjae Sun, Younghan Kim","doi":"10.1109/ICUFN.2017.7993906","DOIUrl":null,"url":null,"abstract":"In recent years, service function chaining (SFC) has been developed besides software-defined networking (SDN) and network function virtualization (NFV), which open new opportunities for flexible provisioning and composition of network services. However, the adoption of SFC requires various security considerations to protect sensitive information in context headers of the network service header (NSH). In this paper, we discuss various SFC encapsulation methods to protect the context headers of the NSH exchanged among service functions. We then implement the SFC encapsulation methods as secure solutions for the context header in NSH. Finally, we conduct an experimental study based on OpenDaylight SFC as an SFC controller and OVS as a data plane to compare the performance of the solutions in term of end-to-end latency.","PeriodicalId":284480,"journal":{"name":"2017 Ninth International Conference on Ubiquitous and Future Networks (ICUFN)","volume":"28 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 Ninth International Conference on Ubiquitous and Future Networks (ICUFN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICUFN.2017.7993906","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
In recent years, service function chaining (SFC) has been developed besides software-defined networking (SDN) and network function virtualization (NFV), which open new opportunities for flexible provisioning and composition of network services. However, the adoption of SFC requires various security considerations to protect sensitive information in context headers of the network service header (NSH). In this paper, we discuss various SFC encapsulation methods to protect the context headers of the NSH exchanged among service functions. We then implement the SFC encapsulation methods as secure solutions for the context header in NSH. Finally, we conduct an experimental study based on OpenDaylight SFC as an SFC controller and OVS as a data plane to compare the performance of the solutions in term of end-to-end latency.