• DocumentCode
    265752
  • Title

    OpenSec: A framework for implementing security policies using OpenFlow

  • Author

    Lara, Adrian ; Ramamurthy, Byrav

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Univ. of Nebraska-Lincoln, Lincoln, NE, USA
  • fYear
    2014
  • fDate
    8-12 Dec. 2014
  • Firstpage
    781
  • Lastpage
    786
  • Abstract
    As the popularity of software defined networks (SDN) and OpenFlow increases, policy-driven network management has received more attention. Manual configuration of multiple devices is being replaced by an automated approach where a software-based, network-aware controller handles the configuration of all network devices. Software applications running on top of the network controller provide an abstraction of the topology and facilitate the task of operating the network. We propose OpenSec, an OpenFlow-based security framework that allows a network security operator to create and implement security policies written in human-readable language. Using OpenSec, the user can describe a flow in terms of OpenFlow matching fields, define which security services must be applied to that flow (deep packet inspection, intrusion detection, spam detection, etc) and specify security levels that define how OpenSec reacts if malicious traffic is detected. We implement OpenSec in the GENI testbed to evaluate the flexibility, accuracy and scalability of the framework. The experimental setup includes deep packet inspection, intrusion detection and network quarantining to secure a web server from network scanners. We achieve a constant delay when reacting to security alerts and a detection rate of 98%.
  • Keywords
    Internet; computer network management; computer network security; software defined networking; telecommunication network topology; telecommunication traffic; GENI testbed; OpenFlow matching fields; OpenFlow-based security framework; OpenSec; Web server; deep packet inspection; human-readable language; intrusion detection; malicious traffic; network quarantining; network scanners; network security; network-aware controller; policy-driven network management; security policies; software applications; software defined networks; software-based controller; Communication networks; Inspection; Ports (Computers); Process control; Security; Switches; Network Security; OpenFlow; Software Defined Networking;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Communications Conference (GLOBECOM), 2014 IEEE
  • Conference_Location
    Austin, TX
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2014.7036903
  • Filename
    7036903