Skip to main content

2018 | OriginalPaper | Buchkapitel

New SDN-Oriented Authentication and Access Control Mechanism

verfasst von : Fahad Nife, Zbigniew Kotulski

Erschienen in: Computer Networks

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Software-Defined Network (SDN) is recognized as one of the most important future networking area. SDN architecture is a revolutionary new idea that, moving the traditional network to be software-based, provides more flexibility, high degree of automation and shorter provision time. SDN architecture dynamically separates the control plane from the data (forwarding) plane of the network, which provides centralized view of the entire network and makes it easier for managing and for monitoring the network’s resources. However, the initial design of the SDN, with its centralized point of control, does not consider sufficiently the security requirements, which makes the security issues additional challenges. In this paper we propose a new access control system for the SDN architecture, working as a controller application used to verify the identity of a host upon connection to the network. The proposed mechanism, which denies the access attempts from unauthorized hosts and defines different levels of privileges for each host, according to its authentication credentials, is implemented using a POX controller. Our approach neither needs a support of new protocols, nor requires additional configuration of hosts or routers.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Pujolle, G.: Software Networks Virtualization, SDN, 5G and Security. ISTE Ltd. and Wiley, London and New York (2015) Pujolle, G.: Software Networks Virtualization, SDN, 5G and Security. ISTE Ltd. and Wiley, London and New York (2015)
2.
Zurück zum Zitat Kreutz, D., Ramos, F.M.V., Verissimo, P.E., Rothenberg, C.E., Azodolmolky, S., Uhlig, S.: Software-defined networking: a comprehensive survey. Proc. IEEE 103, 14–76 (2015)CrossRef Kreutz, D., Ramos, F.M.V., Verissimo, P.E., Rothenberg, C.E., Azodolmolky, S., Uhlig, S.: Software-defined networking: a comprehensive survey. Proc. IEEE 103, 14–76 (2015)CrossRef
3.
Zurück zum Zitat Astuto, B.N., Mendonca, M., Nguyen, X.N., Obraczka, K., Turletti, T.: A survey of software-defined networking: past, present, and future of programmable networks. IEEE Comm. Surv. Tutor. 16, 1617–1634 (2014)CrossRef Astuto, B.N., Mendonca, M., Nguyen, X.N., Obraczka, K., Turletti, T.: A survey of software-defined networking: past, present, and future of programmable networks. IEEE Comm. Surv. Tutor. 16, 1617–1634 (2014)CrossRef
5.
Zurück zum Zitat Hu, F., Hao, Q., Bao, K.: A survey on software-defined network and OpenFlow: from concept to implementation. IEEE Commun. Surv. Tutor. 16(4), 2181–2206 (2014)CrossRef Hu, F., Hao, Q., Bao, K.: A survey on software-defined network and OpenFlow: from concept to implementation. IEEE Commun. Surv. Tutor. 16(4), 2181–2206 (2014)CrossRef
6.
Zurück zum Zitat Lara, A., Kolasani, A., Ramamurthy, B.: Network innovation using OpenFlow: a survey. IEEE Comm. Surv. Tutor. 16, 493–512 (2014)CrossRef Lara, A., Kolasani, A., Ramamurthy, B.: Network innovation using OpenFlow: a survey. IEEE Comm. Surv. Tutor. 16, 493–512 (2014)CrossRef
7.
Zurück zum Zitat Ahmad, I., Namal, S., Ylianttila, M., Gurtov, A.: Security in software defined networks: a survey. IEEE Commun. Surv. Tutor. 17(4), 2317–2346 (2015)CrossRef Ahmad, I., Namal, S., Ylianttila, M., Gurtov, A.: Security in software defined networks: a survey. IEEE Commun. Surv. Tutor. 17(4), 2317–2346 (2015)CrossRef
8.
Zurück zum Zitat Alsmadi, I., Xu, D.: Security of software defined networks: a survey. Comput. Secur. 53, 79–108 (2015)CrossRef Alsmadi, I., Xu, D.: Security of software defined networks: a survey. Comput. Secur. 53, 79–108 (2015)CrossRef
9.
Zurück zum Zitat Local and Metropolitan Area Networks’ Port-Based Network Access Control, IEEE Standard 802.1x (2010) Local and Metropolitan Area Networks’ Port-Based Network Access Control, IEEE Standard 802.1x (2010)
13.
Zurück zum Zitat Jeong, C., Ha, T., Narantuya, J., Lim, H., Kim, J.: scalable network intrusion detection on virtual SDN environment. In: 2014 IEEE 3rd International Conference on Cloud Networking (CloudNet), pp. 264–265, Luxembourg (2014) Jeong, C., Ha, T., Narantuya, J., Lim, H., Kim, J.: scalable network intrusion detection on virtual SDN environment. In: 2014 IEEE 3rd International Conference on Cloud Networking (CloudNet), pp. 264–265, Luxembourg (2014)
14.
Zurück zum Zitat Francois, J., Aib, I., Boutaba, R.: Firecol: a collaborative protection network for the detection of flooding DDoS attacks. IEEE/ACM Trans. Netw. (TON) 20, 1828–1841 (2012)CrossRef Francois, J., Aib, I., Boutaba, R.: Firecol: a collaborative protection network for the detection of flooding DDoS attacks. IEEE/ACM Trans. Netw. (TON) 20, 1828–1841 (2012)CrossRef
15.
Zurück zum Zitat Yoon, C., Park, T., Lee, S., Kang, H., Shin, S., Zhang, Z.: Enabling security functions with SDN: a feasibility study. Comput. Netw. 85(1389–1286), 19–35 (2015)CrossRef Yoon, C., Park, T., Lee, S., Kang, H., Shin, S., Zhang, Z.: Enabling security functions with SDN: a feasibility study. Comput. Netw. 85(1389–1286), 19–35 (2015)CrossRef
16.
Zurück zum Zitat Nife, F., Kotulski, Z.: Multi-level stateful firewall mechanism for software defined networks. In: Gaj, P., Kwiecień, A., Sawicki, M. (eds.) CN 2017. CCIS, vol. 718, pp. 271–286. Springer, Cham (2017)CrossRef Nife, F., Kotulski, Z.: Multi-level stateful firewall mechanism for software defined networks. In: Gaj, P., Kwiecień, A., Sawicki, M. (eds.) CN 2017. CCIS, vol. 718, pp. 271–286. Springer, Cham (2017)CrossRef
18.
Zurück zum Zitat Pena, J.G., Yu, W.E.: Development of a distributed firewall using software defined networking technology. In: 4th IEEE International Conference on Information Science and Technology, pp. 449–452, Shenzhen, China (2014) Pena, J.G., Yu, W.E.: Development of a distributed firewall using software defined networking technology. In: 4th IEEE International Conference on Information Science and Technology, pp. 449–452, Shenzhen, China (2014)
19.
Zurück zum Zitat Casado, M., Freedman, M.J., Pettit, J., Luo, J., McKeown, N., Shenker, S.: Ethane: taking control of the enterprise. In: ACM SIGCOMM, Kyoto, Japan, pp. 1–12 (2007)CrossRef Casado, M., Freedman, M.J., Pettit, J., Luo, J., McKeown, N., Shenker, S.: Ethane: taking control of the enterprise. In: ACM SIGCOMM, Kyoto, Japan, pp. 1–12 (2007)CrossRef
20.
Zurück zum Zitat Nayak, A., Reimers, A., Feamster, N., Clark, R.: Resonance: dynamic access control for enterprise networks. In: Workshop: Research on Enterprise Networking (WREN), Barcelona, Spain (2009) Nayak, A., Reimers, A., Feamster, N., Clark, R.: Resonance: dynamic access control for enterprise networks. In: Workshop: Research on Enterprise Networking (WREN), Barcelona, Spain (2009)
21.
Zurück zum Zitat Dangovas, V., Kuliesius, F.: SDN-driven authentication and access control system. In: The International Conference on Digital Information, Networking, and Wireless Communications (DINWC). Society of Digital Information and Wireless Communication, pp. 20–23 (2014) Dangovas, V., Kuliesius, F.: SDN-driven authentication and access control system. In: The International Conference on Digital Information, Networking, and Wireless Communications (DINWC). Society of Digital Information and Wireless Communication, pp. 20–23 (2014)
22.
Zurück zum Zitat Kuliesius, F., Dangovas, V.: SDN enhanced campus network authentication and access control system. In: 2016 Eighth International Conference on Ubiquitous and Future Networks (ICUFN), pp. 894–899 (2016) Kuliesius, F., Dangovas, V.: SDN enhanced campus network authentication and access control system. In: 2016 Eighth International Conference on Ubiquitous and Future Networks (ICUFN), pp. 894–899 (2016)
24.
Zurück zum Zitat Matias, J., Garay, J., Mendiola, A., Toledo, N., Jacob, E.: FlowNAC: flow-based network access control. In: Third European Workshop on Software-Defined Networks (EWSDN), Budapest, Hungary, pp. 79–84 (2014) Matias, J., Garay, J., Mendiola, A., Toledo, N., Jacob, E.: FlowNAC: flow-based network access control. In: Third European Workshop on Software-Defined Networks (EWSDN), Budapest, Hungary, pp. 79–84 (2014)
25.
Zurück zum Zitat Yakasai, S.T., Guy, C.G.: Flowidentity: software-defined network access control. In: IEEE Conference on Network Function Virtualization and Software Defined Network, pp. 115–120 (2015) Yakasai, S.T., Guy, C.G.: Flowidentity: software-defined network access control. In: IEEE Conference on Network Function Virtualization and Software Defined Network, pp. 115–120 (2015)
27.
Zurück zum Zitat Green, K., Junghyun, A., Keecheon, K.: A study on authentication mechanism in SEaaS for SDN. In: IMCOM 2017, Beppu, Japan (2017) Green, K., Junghyun, A., Keecheon, K.: A study on authentication mechanism in SEaaS for SDN. In: IMCOM 2017, Beppu, Japan (2017)
28.
Zurück zum Zitat Hauser, F., Schmidt, M., Menth, M.: Establishing a session database for SDN using 802.1x and multiple authentication resources. In: IEEE ICC 2017 SAC Symposium SDN & NFV Track, pp. 1–7 (2017) Hauser, F., Schmidt, M., Menth, M.: Establishing a session database for SDN using 802.1x and multiple authentication resources. In: IEEE ICC 2017 SAC Symposium SDN & NFV Track, pp. 1–7 (2017)
29.
Zurück zum Zitat Heller, B. Sherwood, R., McKeown, N.: The controller placement problem. In: First Workshop on Hot Topics in Software Defined Networks, ser. HotSDN 2012, pp. 7–12. ACM, New York (2012) Heller, B. Sherwood, R., McKeown, N.: The controller placement problem. In: First Workshop on Hot Topics in Software Defined Networks, ser. HotSDN 2012, pp. 7–12. ACM, New York (2012)
30.
Zurück zum Zitat Kreutz, D., Ramos, F.M., Verissimo, P.: Towards secure and dependable software-defined networks. In: Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking, ser. HotSDN 2013, pp. 55–60. ACM, New York (2013) Kreutz, D., Ramos, F.M., Verissimo, P.: Towards secure and dependable software-defined networks. In: Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking, ser. HotSDN 2013, pp. 55–60. ACM, New York (2013)
Metadaten
Titel
New SDN-Oriented Authentication and Access Control Mechanism
verfasst von
Fahad Nife
Zbigniew Kotulski
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-319-92459-5_7