StateFit: A security framework for SDN programmable data plane model

Ren Hung Hwang, Van Linh Nguyen, Po Ching Lin

研究成果: Conference contribution同行評審

6 引文 斯高帕斯(Scopus)

摘要

The programmable data plane model of software-defined networks (SDN) continues to gain adoption and support in many enterprise entities such as Google and Barefoot. This leading trend promises to enable flexible mechanisms for handling traffic on SDN switches. In the early stage of its development, few already-in-market proposals exploit the innovative features of a programmable data plane model to provide smart filters on the SDN switches against attack traffic if any. In this work, we therefore propose a security framework, so-called StateFit, which can flexibly filter attack traffic at the SDN programmable switches (data plane). The goal of StateFit is to reduce the latency and the signaling overhead that come along with the centralized architecture of SDN controllers and further provide innovative features for localized security services such as stateful monitoring. The experiment shows that our system is able to not only detect and prevent the attack traffic but also flexibly update the filtering policies and even the whole traffic interpreter onto the connected programmable switches. Following this approach, we believe that the vision of on-demand security services may come true soon.

原文English
主出版物標題Proceedings - 2018 15th International Symposium on Pervasive Systems, Algorithms and Networks, I-SPAN 2018
發行者Institute of Electrical and Electronics Engineers Inc.
頁面168-173
頁數6
ISBN(電子)9781538685341
DOIs
出版狀態Published - 5 2月 2019
事件15th International Symposium on Pervasive Systems, Algorithms and Networks, I-SPAN 2018 - Yichang, China
持續時間: 16 10月 201818 10月 2018

出版系列

名字Proceedings - 2018 15th International Symposium on Pervasive Systems, Algorithms and Networks, I-SPAN 2018

Conference

Conference15th International Symposium on Pervasive Systems, Algorithms and Networks, I-SPAN 2018
國家/地區China
城市Yichang
期間16/10/1818/10/18

指紋

深入研究「StateFit: A security framework for SDN programmable data plane model」主題。共同形成了獨特的指紋。

引用此