메뉴 건너뛰기




Volumn 21, Issue 5, 2016, Pages 764-776

Security in Software-Defined Networking: Threats and Countermeasures

Author keywords

SDN; Security; Security countermeasures; Software defined networking

Indexed keywords

NETWORK ARCHITECTURE; SECURITY SYSTEMS;

EID: 84954324646     PISSN: 1383469X     EISSN: 15728153     Source Type: Journal    
DOI: 10.1007/s11036-016-0676-x     Document Type: Article
Times cited : (169)

References (65)
  • 1
    • 84926636634 scopus 로고    scopus 로고
    • EMC: emotion-aware mobile cloud computing in 5G
    • Chen M, Zhang Y, Li Y, Mao S, Leung V (2015) EMC: emotion-aware mobile cloud computing in 5G. IEEE Netw 29(2):32–38
    • (2015) IEEE Netw , vol.29 , Issue.2 , pp. 32-38
    • Chen, M.1    Zhang, Y.2    Li, Y.3    Mao, S.4    Leung, V.5
  • 2
    • 82755186159 scopus 로고    scopus 로고
    • Advances in cyber-physical systems research
    • Wan J, Yan H, Suo H, Li F (2011) Advances in cyber-physical systems research. KSII Trans Internet Inf Syst 5(11):1891–1908
    • (2011) KSII Trans Internet Inf Syst , vol.5 , Issue.11 , pp. 1891-1908
    • Wan, J.1    Yan, H.2    Suo, H.3    Li, F.4
  • 4
    • 84990937387 scopus 로고    scopus 로고
    • Software-defined networking: why we like it and how we are building on it
    • Cisco Inc. (2013) Software-defined networking: why we like it and how we are building on it. White Paper
    • (2013) White Paper
    • Inc, C.1
  • 6
    • 84959489074 scopus 로고    scopus 로고
    • Software-defined internet of things for smart urban sensing
    • Liu J, Li Y, Chen M, Dong W, Jin D (2015) Software-defined internet of things for smart urban sensing. IEEE Commun Mag 53(9):55–63
    • (2015) IEEE Commun Mag , vol.53 , Issue.9 , pp. 55-63
    • Liu, J.1    Li, Y.2    Chen, M.3    Dong, W.4    Jin, D.5
  • 8
    • 84990927494 scopus 로고    scopus 로고
    • Inter-datacenter WAN with centralized TE using SDN and OpenFlow
    • Google Inc. (2012) Inter-datacenter WAN with centralized TE using SDN and OpenFlow. Open Network Submit
    • (2012) Open Network Submit
    • Inc, G.1
  • 10
    • 84990952440 scopus 로고    scopus 로고
    • VMware NSX. [Online]
    • VMware NSX. [Online] http://www.vmware.com/products/nsx/
  • 11
    • 84990888397 scopus 로고    scopus 로고
    • Nuage Networks VSP. [Online]
    • Nuage Networks VSP. [Online] http://www.nuagenetworks.net/products/virtualized-services-platform/
  • 13
    • 84894478621 scopus 로고    scopus 로고
    • A vision for cloud security
    • Zhang H (2014) A vision for cloud security. Netw Secur 2014(2):12–15
    • (2014) Netw Secur , vol.2014 , Issue.2 , pp. 12-15
    • Zhang, H.1
  • 14
    • 84883734157 scopus 로고    scopus 로고
    • Openflow vulnerability assessment. In: Proceedings of the second ACM SIGCOMM workshop on Hot topics in software defined networking
    • Benton K, Camp L J, Small C (2013) Openflow vulnerability assessment. In: Proceedings of the second ACM SIGCOMM workshop on Hot topics in software defined networking, pp 151–152
    • (2013) pp 151–152
    • Benton, K.1    Camp, L.J.2    Small, C.3
  • 15
    • 84893626159 scopus 로고    scopus 로고
    • Sdn security: a survey. In: IEEE SDN Future Networks and Services (SDN4FNS)
    • Scott-Hayward S, O’Callaghan G, Sezer S (2013) Sdn security: a survey. In: IEEE SDN Future Networks and Services (SDN4FNS), pp 1–7
    • (2013) pp 1–7
    • Scott-Hayward, S.1    O’Callaghan, G.2    Sezer, S.3
  • 16
    • 84925863888 scopus 로고    scopus 로고
    • Software driven networks problem statement
    • Pan P, Nadeau T (2011) Software driven networks problem statement. IETF Internet-Draft
    • (2011) IETF Internet-Draft
    • Pan, P.1    Nadeau, T.2
  • 17
    • 84990924014 scopus 로고    scopus 로고
    • Floodlight controller documentation for developers [Online]. Available:
    • Floodlight controller documentation for developers [Online]. Available: http://www.projectfloodlight.org/floodlight/
  • 19
    • 84990939964 scopus 로고    scopus 로고
    • OpenDaylight.[Online]. Available:
    • OpenDaylight.[Online]. Available: http://www.opendaylight.org
  • 22
    • 84990939972 scopus 로고    scopus 로고
    • Bernardo DV (2014) Software-defined networking and network function virtualization security architecture. Internet Engineering Task Force. [Online]. Available: draft-bernardo-sec-arch- sdnnvfarchitecture-00
    • Bernardo DV (2014) Software-defined networking and network function virtualization security architecture. Internet Engineering Task Force. [Online]. Available: https://tools.ietf.org/html/ draft-bernardo-sec-arch- sdnnvfarchitecture-00
  • 23
    • 84923784594 scopus 로고    scopus 로고
    • Software-defined and virtualized future mobile and wireless networks: a survey
    • Yang M, Li Y, Jin D, Zeng L, Wu X, Vasilakos A (2015) Software-defined and virtualized future mobile and wireless networks: a survey. ACM/Springer Mob Netw Appl 20(1):4–18
    • (2015) ACM/Springer Mob Netw Appl , vol.20 , Issue.1 , pp. 4-18
    • Yang, M.1    Li, Y.2    Jin, D.3    Zeng, L.4    Wu, X.5    Vasilakos, A.6
  • 25
    • 84910149653 scopus 로고    scopus 로고
    • Security of the internet of things: perspectives and challenges
    • Jing Q, Vasilakos A, Wan J, Lu J, Qiu D (2014) Security of the internet of things: perspectives and challenges. Wirel Netw 20(8):2481–2501
    • (2014) Wirel Netw , vol.20 , Issue.8 , pp. 2481-2501
    • Jing, Q.1    Vasilakos, A.2    Wan, J.3    Lu, J.4    Qiu, D.5
  • 26
    • 84893523854 scopus 로고    scopus 로고
    • SDN based inter-technology load balancing leveraged by flow admission control. In: IEEE SDN for Future Networks and Services (SDN4FNS)
    • Namal S, Ahmad I, Gurtov A, Ylianttila M (2013) SDN based inter-technology load balancing leveraged by flow admission control. In: IEEE SDN for Future Networks and Services (SDN4FNS), pp 1–5
    • (2013) pp 1–5
    • Namal, S.1    Ahmad, I.2    Gurtov, A.3    Ylianttila, M.4
  • 27
    • 84990913133 scopus 로고    scopus 로고
    • The transport layer security (TLS) protocol version 1.2 [Online]
    • Dierks T (2008) The transport layer security (TLS) protocol version 1.2 [Online]. Available: http://tools.ietf.org/html/rfc5246
    • (2008) Available:
    • Dierks, T.1
  • 28
    • 84990944387 scopus 로고    scopus 로고
    • Wasserman M, Hartman S (2013) Security analysis of the open networking foundation (ONF) OpenFlow switch specification. Internet Engineering Task Force. [Online]. Available: draft-mrw-SDNec-openflow-analysis-02
    • Wasserman M, Hartman S (2013) Security analysis of the open networking foundation (ONF) OpenFlow switch specification. Internet Engineering Task Force. [Online]. Available: https://tools.ietf.org/html/ draft-mrw-SDNec-openflow-analysis-02
  • 29
    • 78650109005 scopus 로고    scopus 로고
    • FlowChecker: configuration analysis and verification of federated OpenFlow infrastructures. In: Proceedings of the 3rd ACM Workshop on Assurable and Usable Security Configuration
    • Al-Shaer E, Al-Haj S (2010) FlowChecker: configuration analysis and verification of federated OpenFlow infrastructures. In: Proceedings of the 3rd ACM Workshop on Assurable and Usable Security Configuration, pp 37–44
    • (2010) pp 37–44
    • Al-Shaer, E.1    Al-Haj, S.2
  • 30
    • 84866518191 scopus 로고    scopus 로고
    • A security enforcement kernel for OpenFlow networks. In: Proceedings of the First Workshop on Hot Topics in Software Defined Networks
    • Porras P, Shin S, Yegneswaran V, Fong M, Tyson M, Gu G (2012) A security enforcement kernel for OpenFlow networks. In: Proceedings of the First Workshop on Hot Topics in Software Defined Networks, pp 121–126
    • (2012) pp 121–126
    • Porras, P.1    Shin, S.2    Yegneswaran, V.3    Fong, M.4    Tyson, M.5    Gu, G.6
  • 32
    • 84864245314 scopus 로고    scopus 로고
    • A replication component for resilient OpenFlow-based networking. In: IEEE Network Operations and Management Symposium (NOMS)
    • Fonseca P, Bennesby R, Mota E, Passito A (2012) A replication component for resilient OpenFlow-based networking. In: IEEE Network Operations and Management Symposium (NOMS), pp 933–939
    • (2012) pp 933–939
    • Fonseca, P.1    Bennesby, R.2    Mota, E.3    Passito, A.4
  • 34
    • 84055179019 scopus 로고    scopus 로고
    • Source address validation solution with OpenFlow/NOX architecture. In: 19th IEEE International Conference on Network Protocols (ICNP)
    • Yao G, Bi J, Xiao P (2011) Source address validation solution with OpenFlow/NOX architecture. In: 19th IEEE International Conference on Network Protocols (ICNP), pp 7–12
    • (2011) pp 7–12
    • Yao, G.1    Bi, J.2    Xiao, P.3
  • 35
    • 79955041204 scopus 로고    scopus 로고
    • Lightweight DDoS flooding attack detection using NOX/OpenFlow. In: IEEE 35th Conference on Local Computer Networks (LCN)
    • Braga R, Mota E, Passito A (2010) Lightweight DDoS flooding attack detection using NOX/OpenFlow. In: IEEE 35th Conference on Local Computer Networks (LCN), pp 408–415
    • (2010) pp 408–415
    • Braga, R.1    Mota, E.2    Passito, A.3
  • 36
    • 77954339615 scopus 로고    scopus 로고
    • Resonance: dynamic access control for enterprise networks. In: Proceedings of the 1st ACM Workshop on Research on Enterprise Networking
    • Nayak A K, Reimers A, Feamster N, Clark R (2009). Resonance: dynamic access control for enterprise networks. In: Proceedings of the 1st ACM Workshop on Research on Enterprise Networking, pp 11–18
    • (2009) pp 11–18
    • Nayak, A.K.1    Reimers, A.2    Feamster, N.3    Clark, R.4
  • 37
    • 84889062725 scopus 로고    scopus 로고
    • Avant-guard: scalable and vigilant switch flow management in software-defined networks
    • ACM SIGSAC Conference on Computer &, Communications Security
    • Shin S, Yegneswaran V, Porras P, Gu G (2013) Avant-guard: scalable and vigilant switch flow management in software-defined networks. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security, pp 413–424
    • (2013) Proceedings of the , vol.2013 , pp. 413-424
    • Shin, S.1    Yegneswaran, V.2    Porras, P.3    Gu, G.4
  • 38
    • 84950135398 scopus 로고    scopus 로고
    • FloodGuard: a dos attack prevention extension in software-defined networks. In: 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
    • Wang H, Xu L, Gu G (2015) FloodGuard: a dos attack prevention extension in software-defined networks. In: 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), pp 239–250
    • (2015) pp 239–250
    • Wang, H.1    Xu, L.2    Gu, G.3
  • 39
    • 84906715175 scopus 로고    scopus 로고
    • A SDN-oriented DDoS blocking scheme for botnet-based attacks. In: IEEE Sixth International Conference on Ubiquitous and Future Networks (ICUFN)
    • Lim S, Ha J I, Kim H, Kim Y, Yang S (2014) A SDN-oriented DDoS blocking scheme for botnet-based attacks. In: IEEE Sixth International Conference on Ubiquitous and Future Networks (ICUFN), pp 63–68
    • (2014) pp 63–68
    • Lim, S.1    Ha, J.I.2    Kim, H.3    Kim, Y.4    Yang, S.5
  • 40
    • 84990945497 scopus 로고    scopus 로고
    • IETF Locator/ID Separation Protocol (LISP)
    • IETF Locator/ID Separation Protocol (LISP) [Online]. Available: http://datatracker.ietf.org/wg/lisp/
  • 42
    • 84990913466 scopus 로고    scopus 로고
    • Design and deployment of secure, robust, and resilient SDN Controllers. In: 1st IEEE Conference on Network Softwarization (NetSoft)
    • Scott-Hayward S (2015) Design and deployment of secure, robust, and resilient SDN Controllers. In: 1st IEEE Conference on Network Softwarization (NetSoft), pp 1–5
    • (2015) pp 1–5
    • Scott-Hayward, S.1
  • 43
    • 84922330810 scopus 로고    scopus 로고
    • Byzantine-resilient secure software-defined networks with multiple controllers in cloud
    • Li H, Li P, Guo S, Nayak A (2014) Byzantine-resilient secure software-defined networks with multiple controllers in cloud. IEEE Trans Cloud Comput 2(4):436–447
    • (2014) IEEE Trans Cloud Comput , vol.2 , Issue.4 , pp. 436-447
    • Li, H.1    Li, P.2    Guo, S.3    Nayak, A.4
  • 44
    • 84904186178 scopus 로고    scopus 로고
    • Disco: distributed multi-domain sdn controllers. In: IEEE Network Operations and Management Symposium (NOMS)
    • Phemius K, Bouet M, Leguay J (2014) Disco: distributed multi-domain sdn controllers. In: IEEE Network Operations and Management Symposium (NOMS), pp 1–4
    • (2014) pp 1–4
    • Phemius, K.1    Bouet, M.2    Leguay, J.3
  • 45
    • 84990888419 scopus 로고    scopus 로고
    • Developing floodlight modules. floodlight OpenFlow controller Tech
    • Big Switch Inc. (2012) Developing floodlight modules. floodlight OpenFlow controller Tech. Rep.
    • (2012) Rep
    • Inc, B.S.1
  • 46
    • 84990995771 scopus 로고    scopus 로고
    • Advanced message queuing protocol. [Online].
    • Advanced message queuing protocol. [Online]. Available: http://www.amqp.org
  • 47
    • 84866479468 scopus 로고    scopus 로고
    • Scalable software defined network controllers
    • Conference on Applications, Technologies: Architectures, and Protocols for Computer Communication
    • Voellmy A, Wang J (2012) Scalable software defined network controllers. In: Proceedings of the ACM SIGCOMM 2012 Conference on Applications, Technologies, Architectures, and Protocols for Computer Communication, pp 289–290
    • (2012) Proceedings of the ACM SIGCOMM , vol.2012 , pp. 289-290
    • Voellmy, A.1    Wang, J.2
  • 48
    • 84888111404 scopus 로고    scopus 로고
    • HyperFlow: a distributed control plane for OpenFlow
    • Internet Network Management Conference on Research on Enterprise Networking, USENIX Association
    • Tootoonchian A, Ganjali Y (2010) HyperFlow: a distributed control plane for OpenFlow. In: Proceedings of the 2010 Internet Network Management Conference on Research on Enterprise Networking. USENIX Association, pp 3–3
    • (2010) Proceedings of the , vol.2010 , pp. 3
    • Tootoonchian, A.1    Ganjali, Y.2
  • 49
    • 84944193150 scopus 로고    scopus 로고
    • Leveraging software-defined networking for security policy enforcement
    • Liu J et al (2016) Leveraging software-defined networking for security policy enforcement. Inf Sci 327:288–299
    • (2016) Inf Sci , vol.327 , pp. 288-299
    • Liu, J.1
  • 50
    • 84866480420 scopus 로고    scopus 로고
    • The controller placement problem. In: Proceedings of the First Workshop on Hot Topics in Software Defined Networks, ACM
    • Heller B, Sherwood R, McKeown N (2012) The controller placement problem. In: Proceedings of the First Workshop on Hot Topics in Software Defined Networks, ACM, pp 7–12
    • (2012) pp 7–12
    • Heller, B.1    Sherwood, R.2    McKeown, N.3
  • 51
    • 84893599943 scopus 로고    scopus 로고
    • Dynamic controller provisioning in software defined networks. In: 2013 9th IEEE International Conference on Network and Service Management (CNSM)
    • Bari MF, Roy AR, Chowdhury SR, Zhang Q, Zhani MF, Ahmed R, Boutaba R (2013) Dynamic controller provisioning in software defined networks. In: 2013 9th IEEE International Conference on Network and Service Management (CNSM), pp 18–25
    • (2013) pp 18–25
    • Bari, M.F.1    Roy, A.R.2    Chowdhury, S.R.3    Zhang, Q.4    Zhani, M.F.5    Ahmed, R.6    Boutaba, R.7
  • 52
    • 84892633148 scopus 로고    scopus 로고
    • Pareto-optimal resilient controller placement in SDN-based core networks. In: 25th IEEE International Conference on Teletraffic Congress (ITC)
    • Hock D, Hartmann M, Gebert S, Jarschel M, Zinner T, Tran-Gia P (2013) Pareto-optimal resilient controller placement in SDN-based core networks. In: 25th IEEE International Conference on Teletraffic Congress (ITC), pp 1–9
    • (2013) pp 1–9
    • Hock, D.1    Hartmann, M.2    Gebert, S.3    Jarschel, M.4    Zinner, T.5    Tran-Gia, P.6
  • 53
    • 84990944867 scopus 로고    scopus 로고
    • Security-enhanced floodlight. [Online]. Available:. sdncentral.com/education/toward-secure-sdn-controllayer/2013/10/
    • Security-enhanced floodlight. [Online]. Available: http://www. sdncentral.com/education/toward-secure-sdn-controllayer/2013/10/
  • 56
    • 84883671159 scopus 로고    scopus 로고
    • Towards secure and dependable software-defined networks. In: Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking
    • Kreutz D, Ramos F, Verissimo P (2013) Towards secure and dependable software-defined networks. In: Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking, pp 55–60
    • (2013) pp 55–60
    • Kreutz, D.1    Ramos, F.2    Verissimo, P.3
  • 57
    • 84883723129 scopus 로고    scopus 로고
    • Towards a secure controller platform for openflow applications. In: Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking
    • Wen X, Chen Y, Hu C, Shi C, Wang Y (2013) Towards a secure controller platform for openflow applications. In: Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking, pp 171–172
    • (2013) pp 171–172
    • Wen, X.1    Chen, Y.2    Hu, C.3    Shi, C.4    Wang, Y.5
  • 59
    • 84877624157 scopus 로고    scopus 로고
    • Verifiably-safe software-defined networks for CPS. In: Proceedings of the 2nd ACM International Conference on High Confidence Networked Systems, pp
    • Skowyra R, Lapets A, Bestavros A, Kfoury A (2013) Verifiably-safe software-defined networks for CPS. In: Proceedings of the 2nd ACM International Conference on High Confidence Networked Systems, pp. 101–110
    • (2013) 101–110
    • Skowyra, R.1    Lapets, A.2    Bestavros, A.3    Kfoury, A.4
  • 61
    • 84891358075 scopus 로고    scopus 로고
    • I.E. International Conference on Communications (ICC)
    • Son S, Shin S, Yegneswaran V, Porras P, Gu G (2013) Model checking invariant security properties in OpenFlow. In: 2013 I.E. International Conference on Communications (ICC), pp 1974–1979
    • (2013) pp 1974–1979
    • Son, S.1    Shin, S.2    Yegneswaran, V.3    Porras, P.4
  • 63
    • 85076709056 scopus 로고    scopus 로고
    • Real time network policy checking using header space analysis. In: USENIX Symposium on Networked Systems Design and Implementation
    • Kazemian P, Chan M, Zeng H, Varghese G, McKeown N, Whyte S (2013) Real time network policy checking using header space analysis. In: USENIX Symposium on Networked Systems Design and Implementation, pp 99–111
    • (2013) pp 99–111
    • Kazemian, P.1    Chan, M.2    Zeng, H.3    Varghese, G.4    McKeown, N.5    Whyte, S.6
  • 64
    • 85074798835 scopus 로고    scopus 로고
    • Header space analysis: static checking for networks. In: USENIX Symposium on Networked Systems Design and Implementation NSDI
    • Kazemian P, Varghese G, McKeown N (2012) Header space analysis: static checking for networks. In: USENIX Symposium on Networked Systems Design and Implementation NSDI, pp 113–126
    • (2012) pp 113–126
    • Kazemian, P.1    Varghese, G.2    McKeown, N.3
  • 65
    • 84894196540 scopus 로고    scopus 로고
    • Towards a security-enhanced firewall application for openflow networks. In: Cyberspace Safety and Security, Springer International Publishing, pp
    • Wang J, Wang Y, Hu H, Sun Q, Shi H, Zeng L (2013) Towards a security-enhanced firewall application for openflow networks. In: Cyberspace Safety and Security, Springer International Publishing, pp. 92–103
    • (2013) 92–103
    • Wang, J.1    Wang, Y.2    Hu, H.3    Sun, Q.4    Shi, H.5    Zeng, L.6


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.