TY - JOUR
T1 - Software defined networking
T2 - security model, threats and mechanism
AU - Wang, Meng Meng
AU - Liu, Jian Wei
AU - Chen, Jie
AU - Mao, Jian
AU - Mao, Ke Fei
N1 - Publisher Copyright:
© Copyright 2016, Institute of Software, the Chinese Academy of Sciences. All rights reserved.
PY - 2016/4/1
Y1 - 2016/4/1
N2 - Software defined networking (SDN) facilitates rapid and open innovation by decoupling the control plane from the data plane, thus enabling high degree of openness and programmability in network protocols and applications. However, the dynamism of programmable networks also introduces new security challenges, which limit the large-scale application of SDN in many places. This paper presents a comprehensive survey on the security of SDN. First, SDN architecture and the security model of SDN are reviewed. Next, typical security threats and security issues of SDN are summarized and classified from the following two aspects: SDN specific and non-specific threats, and the security issues associated with the SDN framework. Then an in-depth analysis is provided on the latest developments in how to build a secure and dependable SDN from the following six aspects: Building a secure SDN controller or network operating system, the modular composable security services for SDN, DoS/DDoS flooding attack prevention and detection for SDN controllers, conflict resolutions and consistency resolutions for flow rules in SDN, the security of northbound application programming interface (API), and the security of applications in SDN. Finally, a brief analysis of the standardization work on SDN security is provided, along with a discussion on future research trends in building more secured SDN.
AB - Software defined networking (SDN) facilitates rapid and open innovation by decoupling the control plane from the data plane, thus enabling high degree of openness and programmability in network protocols and applications. However, the dynamism of programmable networks also introduces new security challenges, which limit the large-scale application of SDN in many places. This paper presents a comprehensive survey on the security of SDN. First, SDN architecture and the security model of SDN are reviewed. Next, typical security threats and security issues of SDN are summarized and classified from the following two aspects: SDN specific and non-specific threats, and the security issues associated with the SDN framework. Then an in-depth analysis is provided on the latest developments in how to build a secure and dependable SDN from the following six aspects: Building a secure SDN controller or network operating system, the modular composable security services for SDN, DoS/DDoS flooding attack prevention and detection for SDN controllers, conflict resolutions and consistency resolutions for flow rules in SDN, the security of northbound application programming interface (API), and the security of applications in SDN. Finally, a brief analysis of the standardization work on SDN security is provided, along with a discussion on future research trends in building more secured SDN.
KW - Controller security
KW - OpenFlow
KW - Security model
KW - Security protocol of northbound application programming interface
KW - Security threats
KW - Software defined networking
UR - https://www.scopus.com/pages/publications/84965099867
U2 - 10.13328/j.cnki.jos.005020
DO - 10.13328/j.cnki.jos.005020
M3 - 文献综述
AN - SCOPUS:84965099867
SN - 1000-9825
VL - 27
SP - 969
EP - 992
JO - Ruan Jian Xue Bao/Journal of Software
JF - Ruan Jian Xue Bao/Journal of Software
IS - 4
ER -