Mobile SecurityEngineeringInformation SecuritySoftware Defined SecuritySecure Controller PlatformHardware SecurityAccess ControlSystems EngineeringTrusted Execution EnvironmentSecure ComputingOperating System SecurityData PrivacyCustomized Isolation MechanismComputer ScienceIsolation RequirementsData SecurityCryptographySoftware SecurityCloud ComputingSystem Software
The OpenFlow (OF) paradigm embraces third-party development efforts, and therefore suffers from potential trust issue on OF applications (apps). The abuse of such trust could lead to various types of attacks impacting the entire network. In this paper, we propose PermOF, a fine-grained permission system, as the first line of defense, in order to apply minimum privilege on apps. We summarize a set of 18 permissions to be enforced at the API entry of the controller. To accommodate the isolation requirements, we propose a customized isolation mechanism, which achieves comprehensive resource isolation and access control.
5
Natasha Gude, Teemu Koponen, Justin Pettit et al. · ACM SIGCOMM Computer Communication Review · 2008 · 1.4K citations
FlowVisor: A Network Virtualization Layer
Rob Sherwood, Glen Gibb, Kok-Kiong Yap et al. · 2009 · 599 citations
A security enforcement kernel for OpenFlow networks
Philip Porras, Seungwon Shin, Vinod Yegneswaran et al. · 2012 · 520 citations · Full text
Engineering, Information Security, Software Defined Security +19
FRESCO: Modular Composable Security Services for Software-Defined Networks
Seungwon Shin, Phillip Porras, Vinod Yegneswara et al. · 2013 · 488 citations
A NICE way to test openflow applications
Marco Canini, Daniele Venzano, Peter Perešíni et al. · Infoscience (Ecole Polytechnique Fédérale de Lausanne) · 2012 · 417 citations · Full text