增强了SDN路由的安全性

Nurefsan Sertbas Bülbül, Orhan Ermis, Şerif Bahtiyar, M. Çaglayan, Fatih Alagöz
{"title":"增强了SDN路由的安全性","authors":"Nurefsan Sertbas Bülbül, Orhan Ermis, Şerif Bahtiyar, M. Çaglayan, Fatih Alagöz","doi":"10.1109/6gnet54646.2022.9830213","DOIUrl":null,"url":null,"abstract":"Software Defined Networking (SDN) paradigm is the redefinition of conventional networks based on the use of programmable entities together with a clear separation between the data plane and the control plane. The idea behind this new paradigm is to achieve a more flexible network architecture and better management capabilities. However, with all these advantages, it has been experienced that SDNs are open to new security threats and unfortunately, current technologies are not mature enough to overcome those vulnerabilities. As an example, we can consider the detection of the compromised switches in the network. Since switches are programmable entities, in SDN, they are the potential targets for attackers. When a switch is compromised, the attacker can use this switch to deploy incorrect packet forwarding and unsubstantiated packet dropping attacks. Current SDN protocols are not able to detect such kinds of attacks in the network and hence the whole network traffic can be affected in the end. One particular assumption is to use an approach that reflects the trust level of switches in the network for the detection of a compromised one. Therefore, in this paper, we propose Trust Enhanced Security (TES) for routing in SDN. The proposed approach provides three different trust computations to find the most suitable trust level for different states of a network. To show the applicability of the proposed approach, we demonstrate a set of simulations based on the detection of compromised switches. Simulation results show that the proposed model operates effectively to detect and eliminate compromised nodes while selecting secure paths.","PeriodicalId":284215,"journal":{"name":"2022 1st International Conference on 6G Networking (6GNet)","volume":"34 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-07-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Trust Enhanced Security for Routing in SDN\",\"authors\":\"Nurefsan Sertbas Bülbül, Orhan Ermis, Şerif Bahtiyar, M. Çaglayan, Fatih Alagöz\",\"doi\":\"10.1109/6gnet54646.2022.9830213\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Software Defined Networking (SDN) paradigm is the redefinition of conventional networks based on the use of programmable entities together with a clear separation between the data plane and the control plane. The idea behind this new paradigm is to achieve a more flexible network architecture and better management capabilities. However, with all these advantages, it has been experienced that SDNs are open to new security threats and unfortunately, current technologies are not mature enough to overcome those vulnerabilities. As an example, we can consider the detection of the compromised switches in the network. Since switches are programmable entities, in SDN, they are the potential targets for attackers. When a switch is compromised, the attacker can use this switch to deploy incorrect packet forwarding and unsubstantiated packet dropping attacks. Current SDN protocols are not able to detect such kinds of attacks in the network and hence the whole network traffic can be affected in the end. One particular assumption is to use an approach that reflects the trust level of switches in the network for the detection of a compromised one. Therefore, in this paper, we propose Trust Enhanced Security (TES) for routing in SDN. The proposed approach provides three different trust computations to find the most suitable trust level for different states of a network. To show the applicability of the proposed approach, we demonstrate a set of simulations based on the detection of compromised switches. Simulation results show that the proposed model operates effectively to detect and eliminate compromised nodes while selecting secure paths.\",\"PeriodicalId\":284215,\"journal\":{\"name\":\"2022 1st International Conference on 6G Networking (6GNet)\",\"volume\":\"34 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-07-06\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 1st International Conference on 6G Networking (6GNet)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/6gnet54646.2022.9830213\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 1st International Conference on 6G Networking (6GNet)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/6gnet54646.2022.9830213","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

软件定义网络(SDN)范式是基于可编程实体的使用以及数据平面和控制平面之间的明确分离对传统网络的重新定义。这种新范例背后的思想是实现更灵活的网络架构和更好的管理能力。然而,尽管拥有所有这些优势,sdn也面临着新的安全威胁,不幸的是,目前的技术还不够成熟,无法克服这些漏洞。例如,我们可以考虑对网络中受损交换机的检测。由于交换机是可编程实体,在SDN中,它们是攻击者的潜在目标。当交换机被攻破后,攻击者可以利用交换机进行错误的报文转发和未经证实的丢包攻击。目前的SDN协议无法检测到网络中的此类攻击,因此最终会影响整个网络的流量。一个特殊的假设是使用一种方法来反映网络中交换机的信任级别,以检测受损害的交换机。因此,在本文中,我们提出了用于SDN路由的信任增强安全性(TES)。该方法提供了三种不同的信任计算,以找到适合网络不同状态的最合适的信任级别。为了证明所提出方法的适用性,我们演示了一组基于检测受损开关的模拟。仿真结果表明,该模型在选择安全路径的同时能够有效地检测和消除受损节点。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Trust Enhanced Security for Routing in SDN
Software Defined Networking (SDN) paradigm is the redefinition of conventional networks based on the use of programmable entities together with a clear separation between the data plane and the control plane. The idea behind this new paradigm is to achieve a more flexible network architecture and better management capabilities. However, with all these advantages, it has been experienced that SDNs are open to new security threats and unfortunately, current technologies are not mature enough to overcome those vulnerabilities. As an example, we can consider the detection of the compromised switches in the network. Since switches are programmable entities, in SDN, they are the potential targets for attackers. When a switch is compromised, the attacker can use this switch to deploy incorrect packet forwarding and unsubstantiated packet dropping attacks. Current SDN protocols are not able to detect such kinds of attacks in the network and hence the whole network traffic can be affected in the end. One particular assumption is to use an approach that reflects the trust level of switches in the network for the detection of a compromised one. Therefore, in this paper, we propose Trust Enhanced Security (TES) for routing in SDN. The proposed approach provides three different trust computations to find the most suitable trust level for different states of a network. To show the applicability of the proposed approach, we demonstrate a set of simulations based on the detection of compromised switches. Simulation results show that the proposed model operates effectively to detect and eliminate compromised nodes while selecting secure paths.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信