SDN testbed for validation of cross-layer data-centric security policies
Title | SDN testbed for validation of cross-layer data-centric security policies |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Wrona, K., Amanowicz, M., Szwaczyk, S., Gierłowski, K. |
Conference Name | 2017 International Conference on Military Communications and Information Systems (ICMCIS) |
Date Published | May 2017 |
Publisher | IEEE |
ISBN Number | 978-1-5386-3858-3 |
Keywords | Access Control, Communication system security, composability, computer centres, computer network security, Containers, control systems, Cross Layer Security, cross-layer data-centric security policies, Data security, Information security, military computing, OpenFlow-based testbed, operational military systems, Ports (Computers), principal component analysis, pubcrawl, Resiliency, SDN security mechanisms, security, security policies, Servers, Software, software defined networking, software-defined networking, Software-Defined Networks |
Abstract | Software-defined networks offer a promising framework for the implementation of cross-layer data-centric security policies in military systems. An important aspect of the design process for such advanced security solutions is the thorough experimental assessment and validation of proposed technical concepts prior to their deployment in operational military systems. In this paper, we describe an OpenFlow-based testbed, which was developed with a specific focus on validation of SDN security mechanisms - including both the mechanisms for protecting the software-defined network layer and the cross-layer enforcement of higher level policies, such as data-centric security policies. We also present initial experimentation results obtained using the testbed, which confirm its ability to validate simulation and analytic predictions. Our objective is to provide a sufficiently detailed description of the configuration used in our testbed so that it can be easily re-plicated and re-used by other security researchers in their experiments. |
URL | https://ieeexplore.ieee.org/document/7956483 |
DOI | 10.1109/ICMCIS.2017.7956483 |
Citation Key | wrona_sdn_2017 |
- operational military systems
- Software-Defined Networks
- software-defined networking
- software defined networking
- Software
- Servers
- security policies
- security
- SDN security mechanisms
- Resiliency
- pubcrawl
- principal component analysis
- Ports (Computers)
- Access Control
- OpenFlow-based testbed
- military computing
- information security
- Data Security
- cross-layer data-centric security policies
- Cross Layer Security
- control systems
- Containers
- computer network security
- computer centres
- composability
- Communication system security