@inproceedings{463a8781678649ec9530019dfbd410bc,
title = "StateFit: A security framework for SDN programmable data plane model",
abstract = "The programmable data plane model of software-defined networks (SDN) continues to gain adoption and support in many enterprise entities such as Google and Barefoot. This leading trend promises to enable flexible mechanisms for handling traffic on SDN switches. In the early stage of its development, few already-in-market proposals exploit the innovative features of a programmable data plane model to provide smart filters on the SDN switches against attack traffic if any. In this work, we therefore propose a security framework, so-called StateFit, which can flexibly filter attack traffic at the SDN programmable switches (data plane). The goal of StateFit is to reduce the latency and the signaling overhead that come along with the centralized architecture of SDN controllers and further provide innovative features for localized security services such as stateful monitoring. The experiment shows that our system is able to not only detect and prevent the attack traffic but also flexibly update the filtering policies and even the whole traffic interpreter onto the connected programmable switches. Following this approach, we believe that the vision of on-demand security services may come true soon.",
keywords = "ONOS network operating system, P4 programmable language, SDN data plane stateful security, Software-defined network",
author = "Hwang, {Ren Hung} and Nguyen, {Van Linh} and Lin, {Po Ching}",
note = "Publisher Copyright: {\textcopyright} 2018 IEEE.; null ; Conference date: 16-10-2018 Through 18-10-2018",
year = "2019",
month = feb,
day = "5",
doi = "10.1109/I-SPAN.2018.00035",
language = "English",
series = "Proceedings - 2018 15th International Symposium on Pervasive Systems, Algorithms and Networks, I-SPAN 2018",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
pages = "168--173",
booktitle = "Proceedings - 2018 15th International Symposium on Pervasive Systems, Algorithms and Networks, I-SPAN 2018",
address = "United States",
}