TY - GEN
T1 - PERM-GUARD
T2 - 2nd IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2015
AU - Wang, Mengmeng
AU - Liu, Jianwei
AU - Chen, Jie
AU - Liu, Xiao
AU - Mao, Jian
N1 - Publisher Copyright:
© 2015 IEEE.
PY - 2016/1/4
Y1 - 2016/1/4
N2 - Software Defined Networking (SDN) is one of the typical flow-rule-driven networks. In SDN, a centralized controller dictates the network behavior and configures network devices with many flow rules, and the validity and consistency of flow rules could guarantee the normal operations in SDN. Therefore, SDN requires a secure and efficient mechanism to manage and authenticate flow rules between the application layer and the control layer. In this paper, our target problem is to authenticate the validity of flow rules in SDN. We analyze the mechanisms to generate and insert flow rules in SDN respectively, and present PERM-GUARD, a fine-grained flow rule production-permission authentication scheme. PERM-GUARD employs a new permission authentication model and introduces an identity-based signature scheme to ensure that the controller can verify the validity of flow rules. We conduct theoretical analysis and evaluate our approach by simulation. The results demonstrate that PERM-GUARD can efficiently identify and reject fake flow rules generated by unregistered applications. Meanwhile, our approach can also effectively filter unauthorized flow rules created by valid applications.
AB - Software Defined Networking (SDN) is one of the typical flow-rule-driven networks. In SDN, a centralized controller dictates the network behavior and configures network devices with many flow rules, and the validity and consistency of flow rules could guarantee the normal operations in SDN. Therefore, SDN requires a secure and efficient mechanism to manage and authenticate flow rules between the application layer and the control layer. In this paper, our target problem is to authenticate the validity of flow rules in SDN. We analyze the mechanisms to generate and insert flow rules in SDN respectively, and present PERM-GUARD, a fine-grained flow rule production-permission authentication scheme. PERM-GUARD employs a new permission authentication model and introduces an identity-based signature scheme to ensure that the controller can verify the validity of flow rules. We conduct theoretical analysis and evaluate our approach by simulation. The results demonstrate that PERM-GUARD can efficiently identify and reject fake flow rules generated by unregistered applications. Meanwhile, our approach can also effectively filter unauthorized flow rules created by valid applications.
KW - Flow Rule Production-Permissions Management
KW - Flow-Rule-Validity Authentication
KW - Identity-Based Signature
KW - Software Defined Networking
UR - https://www.scopus.com/pages/publications/84962889635
U2 - 10.1109/CSCloud.2015.89
DO - 10.1109/CSCloud.2015.89
M3 - 会议稿件
AN - SCOPUS:84962889635
T3 - Proceedings - 2nd IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2015 - IEEE International Symposium of Smart Cloud, IEEE SSC 2015
SP - 127
EP - 132
BT - Proceedings - 2nd IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2015 - IEEE International Symposium of Smart Cloud, IEEE SSC 2015
A2 - Zhang, Tao
A2 - Das, Sajal K.
A2 - Zhang, Tao
A2 - Qiu, Meikang
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 3 November 2015 through 5 November 2015
ER -