...
首页> 外文期刊>International Journal of Network Management >On network operating system security
【24h】

On network operating system security

机译:关于网络操作系统的安全性

获取原文
获取原文并翻译 | 示例
           

摘要

The emerging concept of software-defined networking (SDN) enables new opportunities for building future networks. In such setups, a so-called network operating system (NOS), which is also known as SDN controller, provides services to manage the underlying and programmable network infrastructure. On top, the so-called SDN applications leverage NOS services and implement business needs in order to orchestrate the network as required. Thereby, such applications have access to all kinds of operations (including critical ones) to use valuable NOS and SDN resources. In case of faulty and malicious SDN applications, we demonstrate that today's NOSs can be significantly harmed, for example, by fatal errors and the adverse use of critical operations. To tackle this problem, we propose a sandbox system, which allows us to restrict not only SDN applications but also internal NOS components to access only a configurable set of critical operations. This enables operators to prevent the entire NOS from crashing in case a single SDN application or NOS component runs into a fatal error. Furthermore, operators can deny access to unwanted critical operations in order to prevent the potential misuse of such operations. For our proposal, we provide two proof-of-concept implementations: one for the industry's leading open-source NOS called OpenDaylight and another one for the HP controller, which serves as foundation for the world's first SDN App Store. As a result of our work, we harden a mandatory SDN component, that is, the NOS, and achieve robustness as well as pro-active security against faulty and malicious SDN software. Copyright © 2015 John Wiley & Sons, Ltd.
机译:新兴的软件定义网络(SDN)概念为构建未来的网络提供了新的机会。在这样的设置中,所谓的网络操作系统(NOS)(也称为SDN控制器)提供服务来管理基础和可编程网络基础结构。最重要的是,所谓的SDN应用程序利用NOS服务并实现业务需求,以便根据需要协调网络。因此,此类应用程序可以访问各种操作(包括关键操作),以使用宝贵的NOS和SDN资源。在出现故障和恶意SDN应用程序的情况下,我们证明了当今的NOS可能受到严重损害,例如致命错误和关键操作的不当使用。为了解决这个问题,我们提出了一个沙盒系统,该系统不仅可以限制SDN应用程序,而且还可以限制内部NOS组件以仅访问一组可配置的关键操作。这样,如果单个SDN应用程序或NOS组件遇到致命错误,操作员就可以防止整个NOS崩溃。此外,操作员可以拒绝访问不需要的关键操作,以防止对此类操作的潜在滥用。对于我们的建议,我们提供了两种概念验证实施:一种用于业界领先的开源NOS(称为OpenDaylight),另一种用于HP控制器,后者是全球首个SDN App Store的基础。由于我们的工作,我们加强了强制性的SDN组件,即NOS,并实现了针对故障和恶意SDN软件的鲁棒性和主动安全性。版权所有©2015 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号