• DocumentCode
    710603
  • Title

    Towards trusted software-defined networks using a hardware-based Integrity Measurement Architecture

  • Author

    Jacquin, Ludovic ; Shaw, Adrian L. ; Dalton, Chris

  • Author_Institution
    HP Labs., Hewlett Packard Labs., Bristol, UK
  • fYear
    2015
  • fDate
    13-17 April 2015
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    The rise of software-defined networks in recent years has allowed unprecedented agility in network configuration and orchestration. As physical links and configurations become virtualised, this has created many opportunities for dynamic and transparent deployment of services. This however, opens up a potential attack surface for new forms of attack. Thus, with the combination of SDN elements abstracting their administration to network administrators and the growing attack surface in network element software, this creates the possibility for malicious routers which do not comply with the higher-level abstractions used by their respective controllers. This paper focuses on building an assurable SDN network using Trusted computing mechanisms to: (A) provide a strong hardware-based platform identity to check that network element software is healthy, and (B) increase assurance that traffic flows are being forwarded to their intended destinations by dynamically monitoring the low-level configurations used to route virtual LANs. The architecture as a whole provides a mechanism to check the network posture, bridging the gap between the areas of remote attestation and virtual networking.
  • Keywords
    computer network management; computer network security; local area networks; software defined networking; telecommunication network routing; telecommunication traffic; trusted computing; virtualisation; SDN elements; attack surface; dynamic transparent service deployment; dynamically monitoring; hardware-based integrity measurement architecture; hardware-based platform identity; higher-level abstractions; low-level configurations; malicious routers; network administrators; network configuration; network element software; network element software checking; network orchestration; network posture checking; physical links; remote attestation; traffic flows assurance; trusted software-defined networks; virtual LAN routing; virtual networking; virtualised configurations; Computer architecture; Hardware; Monitoring; Protocols; Security; Software; Software measurement;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Softwarization (NetSoft), 2015 1st IEEE Conference on
  • Conference_Location
    London
  • Type

    conf

  • DOI
    10.1109/NETSOFT.2015.7116186
  • Filename
    7116186