Towards comprehensive protection for OpenFlow controllers
Title | Towards comprehensive protection for OpenFlow controllers |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Zhang, S., Jia, X., Zhang, W. |
Conference Name | 2017 19th Asia-Pacific Network Operations and Management Symposium (APNOMS) |
Date Published | Sept. 2017 |
Publisher | IEEE |
ISBN Number | 978-1-5386-1101-2 |
Keywords | adaptive networks, agile networks, attack vectors, composability, Computer architecture, Computer bugs, computer network security, control logic, control plane-data ploane decoupling, control systems, cross layer diversity, Cross Layer Security, dynamic networks, industrial control systems, malicious controller, OpenFlow controller, OpenFlow critical component, Operating systems, pubcrawl, Resiliency, security, telecommunication control, Virtual machine monitors |
Abstract | OpenFlow has recently emerged as a powerful paradigm to help build dynamic, adaptive and agile networks. By decoupling control plane from data plane, OpenFlow allows network operators to program a centralized intelligence, OpenFlow controller, to manage network-wide traffic flows to meet the changing needs. However, from the security's point of view, a buggy or even malicious controller could compromise the control logic, and then the entire network. Even worse, the recent attack Stuxnet on industrial control systems also indicates the similar, severe threat to OpenFlow controllers from the commercial operating systems they are running on. In this paper, we comprehensively studied the attack vectors against the OpenFlow critical component, controller, and proposed a cross layer diversity approach that enables OpenFlow controllers to detect attacks, corruptions, failures, and then automatically continue correct execution. Case studies demonstrate that our approach can protect OpenFlow controllers from threats coming from compromised operating systems and themselves. |
URL | https://ieeexplore.ieee.org/document/8094183/ |
DOI | 10.1109/APNOMS.2017.8094183 |
Citation Key | zhang_towards_2017 |
- Cross Layer Security
- Virtual machine monitors
- telecommunication control
- security
- Resiliency
- pubcrawl
- operating systems
- OpenFlow critical component
- OpenFlow controller
- malicious controller
- Industrial Control Systems
- dynamic networks
- adaptive networks
- cross layer diversity
- control systems
- control plane-data ploane decoupling
- control logic
- computer network security
- Computer bugs
- computer architecture
- composability
- Attack vectors
- agile networks