首页> 外文期刊>Communications surveys & tutorials >Comparative Analysis of Control Plane Security of SDN and Conventional Networks
【24h】

Comparative Analysis of Control Plane Security of SDN and Conventional Networks

机译:SDN与常规网络控制平面安全性的比较分析

获取原文
获取原文并翻译 | 示例

摘要

Software defined networking implements the network control plane in an external entity, rather than in each individual device as in conventional networks. This architectural difference implies a different design for control functions necessary for essential network properties, e.g., loop prevention and link redundancy. We explore how such differences redefine the security weaknesses in the SDN control plane and provide a framework for comparative analysis which focuses on essential network properties required by typical production networks. This enables analysis of how these properties are delivered by the control planes of SDN and conventional networks, and to compare security threats and mitigations. Despite the architectural difference, we find similar, but not identical, exposures in control plane security if both network paradigms provide the same network properties and are analyzed under the same threat model. However, defenses vary; SDN cannot depend on edge based filtering to protect its control plane, while this is arguably the primary defense in conventional networks. Our concrete security analysis suggests that a distributed SDN architecture that supports fault tolerance and consistency checks is important for SDN control plane security. Our analysis methodology may be of independent interest for future security analysis of SDN and conventional networks.
机译:软件定义的网络在外部实体中而不是在常规网络中的每个单独设备中实现网络控制平面。这种架构上的差异意味着对于基本网络属性所必需的控制功能的不同设计,例如环路预防和链路冗余。我们探索这种差异如何重新定义SDN控制平面中的安全弱点,并为比较分析提供一个框架,该框架侧重于典型生产网络所需的基本网络属性。这样可以分析SDN和常规网络的控制平面如何传递这些属性,并比较安全威胁和缓解措施。尽管在架构上存在差异,但如果两个网络范例都提供相同的网络属性并在相同的威胁模型下进行分析,我们会发现控制平面安全性方面的相似但不相同。但是,防御措施各不相同。 SDN不能依靠基于边缘的过滤来保护其控制平面,而这可以说是常规网络中的主要防御手段。我们的具体安全性分析表明,支持容错和一致性检查的分布式SDN架构对于SDN控制平面安全性很重要。我们的分析方法可能对SDN和常规网络的未来安全性分析具有独立的兴趣。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号