A Security Evaluation Framework for Software-Defined Network Architectures in Data Center Environments

Igor Ivkic, Dominik Thiede, N. Race, M. Broadbent, Antonios Gouglidis
{"title":"A Security Evaluation Framework for Software-Defined Network Architectures in Data Center Environments","authors":"Igor Ivkic, Dominik Thiede, N. Race, M. Broadbent, Antonios Gouglidis","doi":"10.48550/arXiv.2304.05776","DOIUrl":null,"url":null,"abstract":"The importance of cloud computing has grown over the last years, which resulted in a significant increase of Data Center (DC) network requirements. Virtualisation is one of the key drivers of that transformation and enables a massive deployment of computing resources, which exhausts server capacity limits. Furthermore, the increased network endpoints need to be handled dynamically and centrally to facilitate cloud computing functionalities. Traditional DCs barely satisfy those demands because of their inherent limitations based on the network topology. Software-Defined Networks (SDN) promise to meet the increasing network requirements for cloud applications by decoupling control functionalities from data forwarding. Although SDN solutions add more flexibility to DC networks, they also pose new vulnerabilities with a high impact due to the centralised architecture. In this paper we propose an evaluation framework for assessing the security level of SDN architectures in four different stages. Furthermore, we show in an experimental study, how the framework can be used for mapping SDN threats with associated vulnerabilities and necessary mitigations in conjunction with risk and impact classification. The proposed framework helps administrators to evaluate the network security level, to apply countermeasures for identified SDN threats, and to meet the networks security requirements.","PeriodicalId":446929,"journal":{"name":"International Conference on Cloud Computing and Services Science","volume":"53 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-04-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Conference on Cloud Computing and Services Science","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.48550/arXiv.2304.05776","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The importance of cloud computing has grown over the last years, which resulted in a significant increase of Data Center (DC) network requirements. Virtualisation is one of the key drivers of that transformation and enables a massive deployment of computing resources, which exhausts server capacity limits. Furthermore, the increased network endpoints need to be handled dynamically and centrally to facilitate cloud computing functionalities. Traditional DCs barely satisfy those demands because of their inherent limitations based on the network topology. Software-Defined Networks (SDN) promise to meet the increasing network requirements for cloud applications by decoupling control functionalities from data forwarding. Although SDN solutions add more flexibility to DC networks, they also pose new vulnerabilities with a high impact due to the centralised architecture. In this paper we propose an evaluation framework for assessing the security level of SDN architectures in four different stages. Furthermore, we show in an experimental study, how the framework can be used for mapping SDN threats with associated vulnerabilities and necessary mitigations in conjunction with risk and impact classification. The proposed framework helps administrators to evaluate the network security level, to apply countermeasures for identified SDN threats, and to meet the networks security requirements.
数据中心环境下软件定义网络架构的安全评估框架
云计算的重要性在过去几年中不断增长,这导致了数据中心(DC)网络需求的显著增加。虚拟化是这一转变的关键驱动因素之一,它能够大规模部署计算资源,从而耗尽服务器的容量限制。此外,需要动态和集中地处理增加的网络端点,以促进云计算功能。传统数据中心由于其基于网络拓扑的固有限制,很难满足这些需求。软件定义网络(SDN)通过将控制功能与数据转发分离来满足云应用日益增长的网络需求。尽管SDN解决方案为数据中心网络增加了更多的灵活性,但由于集中式架构,它们也带来了新的漏洞,影响很大。在本文中,我们提出了一个评估框架,用于评估SDN架构在四个不同阶段的安全级别。此外,我们在一项实验研究中展示了如何将该框架用于映射带有相关漏洞的SDN威胁以及与风险和影响分类相结合的必要缓解措施。该框架有助于管理员评估网络的安全级别,并针对已识别的SDN威胁采取相应的应对措施,满足网络安全需求。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信
小红书