...
首页> 外文期刊>Communications Surveys & Tutorials, IEEE >A Survey on the Security of Stateful SDN Data Planes
【24h】

A Survey on the Security of Stateful SDN Data Planes

机译:有状态SDN数据平面的安全性调查

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Software-defined networking (SDN) emerged as an attempt to introduce network innovations faster, and to radically simplify and automate the management of large networks. SDN traditionally leverages OpenFlow as device-level abstraction. Since OpenFlow permits the programmer to “just” abstract a static flow-table, any stateful control and processing intelligence is necessarily delegated to the network controller. Motivated by the latency and signaling overhead that comes along with such a two-tiered SDN programming model, in the last couple of years several works have proposed innovative switch-level (data plane) programming abstractions capable to deploy some smartness directly inside the network switches, e.g., in the form of localized stateful flow processing. Furthermore, the possible inclusion of states and state maintenance primitives inside the switches is currently being debated in the OpenFlow standardization community itself. In this paper, after having provided the reader with a background on such emerging stateful SDN data plane proposals, we focus our attention on the security implications that data plane programmability brings about. Also via the identification of potential attack scenarios, we specifically highlight possible vulnerabilities specific to stateful in-switch processing (including denial of service and saturation attacks), which we believe should be carefully taken into consideration in the ongoing design of current and future proposals for stateful SDN data planes.
机译:软件定义网络(SDN)的出现是为了尝试更快地引入网络创新,并从根本上简化和自动化大型网络的管理。 SDN传统上将OpenFlow用作设备级抽象。由于OpenFlow允许程序员“仅”提取静态流表,因此任何有状态的控制和处理智能都必须委托给网络控制器。受这样的两层SDN编程模型所带来的延迟和信令开销的影响,在最近几年中,有几项工作提出了创新的交换机级(数据平面)编程抽象,该抽象能够在网络交换机内部直接部署一些智能功能。例如,以局部状态流处理的形式。此外,目前在OpenFlow标准化社区本身中正在讨论在交换机内部可能包含状态和状态维护原语的问题。本文在为读者提供了有关此类新兴的有状态SDN数据平面建议的背景之后,我们将注意力集中在数据平面可编程性带来的安全隐患上。此外,通过识别潜在的攻击情形,我们特别强调了有状态的交换机内处理特有的可能漏洞(包括拒绝服务和饱和攻击),我们认为在当前和将来针对该方案的持续设计中应仔细考虑这些漏洞。有状态的SDN数据平面。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号