Skip to main navigation Skip to search Skip to main content

PERM-GUARD: Authenticating the Validity of Flow Rules in Software Defined Networking

  • Beihang University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Software Defined Networking (SDN) is one of the typical flow-rule-driven networks. In SDN, a centralized controller dictates the network behavior and configures network devices with many flow rules, and the validity and consistency of flow rules could guarantee the normal operations in SDN. Therefore, SDN requires a secure and efficient mechanism to manage and authenticate flow rules between the application layer and the control layer. In this paper, our target problem is to authenticate the validity of flow rules in SDN. We analyze the mechanisms to generate and insert flow rules in SDN respectively, and present PERM-GUARD, a fine-grained flow rule production-permission authentication scheme. PERM-GUARD employs a new permission authentication model and introduces an identity-based signature scheme to ensure that the controller can verify the validity of flow rules. We conduct theoretical analysis and evaluate our approach by simulation. The results demonstrate that PERM-GUARD can efficiently identify and reject fake flow rules generated by unregistered applications. Meanwhile, our approach can also effectively filter unauthorized flow rules created by valid applications.

Original languageEnglish
Title of host publicationProceedings - 2nd IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2015 - IEEE International Symposium of Smart Cloud, IEEE SSC 2015
EditorsTao Zhang, Sajal K. Das, Tao Zhang, Meikang Qiu
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages127-132
Number of pages6
ISBN (Electronic)9781467392990
DOIs
StatePublished - 4 Jan 2016
Event2nd IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2015 - New York, United States
Duration: 3 Nov 20155 Nov 2015

Publication series

NameProceedings - 2nd IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2015 - IEEE International Symposium of Smart Cloud, IEEE SSC 2015

Conference

Conference2nd IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2015
Country/TerritoryUnited States
CityNew York
Period3/11/155/11/15

Keywords

  • Flow Rule Production-Permissions Management
  • Flow-Rule-Validity Authentication
  • Identity-Based Signature
  • Software Defined Networking

Fingerprint

Dive into the research topics of 'PERM-GUARD: Authenticating the Validity of Flow Rules in Software Defined Networking'. Together they form a unique fingerprint.

Cite this