Bassey Isong, Tebogo Kgogo, Francis Lugayizi, Bennett Kankuzi
{"title":"Trust establishment framework between SDN controller and applications","authors":"Bassey Isong, Tebogo Kgogo, Francis Lugayizi, Bennett Kankuzi","doi":"10.1109/SNPD.2017.8022707","DOIUrl":null,"url":null,"abstract":"Software Defined Networks (SDNs) is a new network paradigm and is gaining significant attention in recent years. However, security remains a great challenge, though several improvements have been proposed. A key security challenge is the lack of trust between the SDN controller and the applications running atop the control plane. SDN controller can easily be attacked if these applications are malicious or compromised by an attacker to control the entire network or even result in network failure since it represents a single point of failure in the SDN. Though trust mechanisms to verify network devices exist, mechanisms to verify management applications are still not well developed. Therefore, this paper proposes a unique direct trust establishment framework between an OpenFlow-based SDN controller and the applications. The objective is to ensure that SDN controller is protected and multitude of applications that regularly consume network resources are always trusted throughout their lifetime. Additionally, the paper introduced the concept of trust access matrix and application identity to ensure efficient control of network resources. Based on its operation, if this proposed trust model is adopted in the OpenFlow architecture, it could go a long way to improve the security of the SDN and protect the controller.","PeriodicalId":186094,"journal":{"name":"2017 18th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD)","volume":"10 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 18th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SNPD.2017.8022707","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 12
Abstract
Software Defined Networks (SDNs) is a new network paradigm and is gaining significant attention in recent years. However, security remains a great challenge, though several improvements have been proposed. A key security challenge is the lack of trust between the SDN controller and the applications running atop the control plane. SDN controller can easily be attacked if these applications are malicious or compromised by an attacker to control the entire network or even result in network failure since it represents a single point of failure in the SDN. Though trust mechanisms to verify network devices exist, mechanisms to verify management applications are still not well developed. Therefore, this paper proposes a unique direct trust establishment framework between an OpenFlow-based SDN controller and the applications. The objective is to ensure that SDN controller is protected and multitude of applications that regularly consume network resources are always trusted throughout their lifetime. Additionally, the paper introduced the concept of trust access matrix and application identity to ensure efficient control of network resources. Based on its operation, if this proposed trust model is adopted in the OpenFlow architecture, it could go a long way to improve the security of the SDN and protect the controller.