DocumentCode :
2738937
Title :
Trust support for SDN controllers and virtualized network applications
Author :
Betge-Brezetz, Stephane ; Kamga, Guy-Bertrand ; Tazi, Monsef
Author_Institution :
Alcatel-Lucent Bell Labs., Nozay, France
fYear :
2015
fDate :
13-17 April 2015
Firstpage :
1
Lastpage :
5
Abstract :
The SDN paradigm allows networks to be dynamically reconfigurable by network applications. SDN is also of particular interest for NFV which deals with the virtualization of network functions. The network programmability offered by SDN presents then various advantages but it also induces various threats regarding potential attacks on the network. For instance, there is a critical risk that a hacker takes over the network control by exploiting this SDN network programmability (e.g., using the SDN API or tampering a network application running on the SDN controller). This paper proposes then an approach to deal with this possible lack of trust in the SDN controller or in their applications. This approach consists in not relying on a single controller but on several `redundant´ controllers that may also run in different execution environments. The network configuration requests coming from these controllers are then compared and, if deemed sufficiently consistent and then trustable, they are actually sent to the network. This approach has been implemented in an intermediary layer (based on a network hypervisor) inserted between the network equipments and the controllers. Experimentations have been performed showing the feasibility of the approach and providing some first evaluations of its impact on the network and the services.
Keywords :
application program interfaces; computer network security; software defined networking; trusted computing; virtualisation; NFV; SDN API; SDN controllers; SDN network programmability; SDN paradigm; network configuration requests; network control; network equipments; network function virtualization; network hypervisor; network programmability; redundant controllers; trust support; virtualized network applications; Computer architecture; Network topology; Prototypes; Routing; Security; Virtual machine monitors; Virtualization; NFV; SDN; network applications; network hypervisor; network virtualization; security; trust;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Softwarization (NetSoft), 2015 1st IEEE Conference on
Conference_Location :
London
Type :
conf
DOI :
10.1109/NETSOFT.2015.7116153
Filename :
7116153
Link To Document :
بازگشت