Please use this identifier to cite or link to this item:
https://hdl.handle.net/1959.11/56627
Title: | Counteracting Attacks from Malicious End Hosts in Software Defined Networks |
Contributor(s): | Varadharajan, Vijay (author); Tupakula, Udaya (author) |
Publication Date: | 2020-03 |
Early Online Version: | 2019-07-26 |
DOI: | 10.1109/TNSM.2019.2931294 |
Handle Link: | https://hdl.handle.net/1959.11/56627 |
Abstract: | | This paper proposes security techniques for counteracting attacks from malicious end hosts in a software defined networking (SDN) environment. This paper describes the design of a security architecture, which comprises a security management application running in the SDN controller for specifying and evaluating security policies, and security components in the switches for enforcing these security policies on network flows. Our proposed security solution helps to detect the attacking end hosts even before the flow requests from the malicious end hosts are forwarded to the SDN controller. Furthermore, if the end hosts become malicious after the interactions with the SDN controller and generate attacks in the data plane, then our architecture has mechanisms to address these attacks that occur after the establishment of routes by the SDN controller. The domain wide network visibility of the SDN controller enables our security architecture to achieve dynamic management of the security policies. The enforcement of security policies in the data plane is tailored to the functionality available in the network switches, making the proposed security solution practical. We describe the implementation of the proposed security architecture and analyze its security and performance characteristics. We also discuss the advantages of the proposed security architecture over existing solutions.
Publication Type: | Journal Article |
Source of Publication: | IEEE Transactions on Network and Service Management, 17(1), p. 160-174 |
Publisher: | Institute of Electrical and Electronics Engineers |
Place of Publication: | United States |
ISSN: | 1932-4537 |
Fields of Research (FoR) 2020: | 460407 System and network security |
Socio-Economic Objective (SEO) 2020: | 220405 Cybersecurity |
Peer Reviewed: | Yes |
HERDC Category Description: | C1 Refereed Article in a Scholarly Journal |
Appears in Collections: | Journal Article School of Science and Technology
|
Show full item record
Items in Research UNE are protected by copyright, with all rights reserved, unless otherwise indicated.