2013 · 234 citations · 11 references
Network VirtualizationEngineeringSoftware-defined InfrastructureSoftware-defined NetworkingInformation SecurityProgram AnalysisSecurity AnalysisCloud ComputingComputer EngineeringComputer ScienceSoftware Defined SecurityEmulated Network TestbedOpenflow NetworksNetworking ParadigmSoftware AnalysisData SecurityCryptographyNetwork Security
Software Defined Networking (SDN) has been proposed as a drastic shift in the networking paradigm, by decoupling network control from the data plane and making the switching infrastructure truly programmable. The key enabler of SDN, OpenFlow, has seen widespread deployment on production networks and its adoption is constantly increasing. Although openness and programmability are primary features of OpenFlow, security is of core importance for real-world deployment. In this work, we perform a security analysis of OpenFlow using STRIDE and attack tree modeling methods, and we evaluate our approach on an emulated network testbed. The evaluation assumes an attacker model with access to the network data plane. Finally, we propose appropriate counter-measures that can potentially mitigate the security issues associated with OpenFlow networks. Our analysis and evaluation approach are not exhaustive, but are intended to be adaptable and extensible to new versions and deployment contexts of OpenFlow.
11
Nick McKeown, Tom Anderson, Hari Balakrishnan et al. · ACM SIGCOMM Computer Communication Review · 2008 · 8.3K citations
Ethernet Switch, Engineering, High Performance Computer Network +13
A security enforcement kernel for OpenFlow networks
Philip Porras, Seungwon Shin, Vinod Yegneswaran et al. · 2012 · 520 citations · Full text
Engineering, Information Security, Software Defined Security +19
Reproducible network experiments using container-based emulation
Nikhil Handigol, Brandon Heller, Vimalkumar Jeyakumar et al. · 2012 · 497 citations
Jafar Haadi Jafarian, Ehab Al‐Shaer, Qi Duan · 2012 · 495 citations