DocumentCode :
710603
Title :
Towards trusted software-defined networks using a hardware-based Integrity Measurement Architecture
Author :
Jacquin, Ludovic ; Shaw, Adrian L. ; Dalton, Chris
Author_Institution :
HP Labs., Hewlett Packard Labs., Bristol, UK
fYear :
2015
fDate :
13-17 April 2015
Firstpage :
1
Lastpage :
6
Abstract :
The rise of software-defined networks in recent years has allowed unprecedented agility in network configuration and orchestration. As physical links and configurations become virtualised, this has created many opportunities for dynamic and transparent deployment of services. This however, opens up a potential attack surface for new forms of attack. Thus, with the combination of SDN elements abstracting their administration to network administrators and the growing attack surface in network element software, this creates the possibility for malicious routers which do not comply with the higher-level abstractions used by their respective controllers. This paper focuses on building an assurable SDN network using Trusted computing mechanisms to: (A) provide a strong hardware-based platform identity to check that network element software is healthy, and (B) increase assurance that traffic flows are being forwarded to their intended destinations by dynamically monitoring the low-level configurations used to route virtual LANs. The architecture as a whole provides a mechanism to check the network posture, bridging the gap between the areas of remote attestation and virtual networking.
Keywords :
computer network management; computer network security; local area networks; software defined networking; telecommunication network routing; telecommunication traffic; trusted computing; virtualisation; SDN elements; attack surface; dynamic transparent service deployment; dynamically monitoring; hardware-based integrity measurement architecture; hardware-based platform identity; higher-level abstractions; low-level configurations; malicious routers; network administrators; network configuration; network element software; network element software checking; network orchestration; network posture checking; physical links; remote attestation; traffic flows assurance; trusted software-defined networks; virtual LAN routing; virtual networking; virtualised configurations; Computer architecture; Hardware; Monitoring; Protocols; Security; Software; Software measurement;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Softwarization (NetSoft), 2015 1st IEEE Conference on
Conference_Location :
London
Type :
conf
DOI :
10.1109/NETSOFT.2015.7116186
Filename :
7116186
Link To Document :
بازگشت