Visible to the public HEX Switch: Hardware-Assisted Security Extensions of OpenFlow

TitleHEX Switch: Hardware-Assisted Security Extensions of OpenFlow
Publication TypeConference Paper
Year of Publication2018
AuthorsPark, Taejune, Xu, Zhaoyan, Shin, Seungwon
Conference NameProceedings of the 2018 Workshop on Security in Softwarized Networks: Prospects and Challenges
PublisherACM
ISBN Number978-1-4503-5912-2
KeywordsNetFPGA, pubcrawl, resilience, Resiliency, Scalability, SDN, SDN security, security
Abstract

Software-defined networking (SDN) and Network Function Virtualization (NFV) have inspired security researchers to devise new security applications for these new network technology. However, since SDN and NFV are basically faithful to operating a network, they only focus on providing features related to network control. Therefore, it is challenging to implement complex security functions such as packet payload inspection. Several studies have addressed this challenge through an SDN data plane extension, but there were problems with performance and control interfaces. In this paper, we introduce a new data plane architecture, HEX which leverages existing data plane architectures for SDN to enable network security applications in an SDN environment efficiently and effectively. HEX provides security services as a set of OpenFlow actions ensuring high performance and a function of handling multiple SDN actions with a simple control command. We implemented a DoS detector and Deep Packet Inspection (DPI) as the prototype features of HEX using the NetFPGA-1G-CML, and our evaluation results demonstrate that HEX can provide security services as a line-rate performance.

URLhttps://dl.acm.org/citation.cfm?doid=3229616.3229622
DOI10.1145/3229616.3229622
Citation Keypark_hex_2018