Implementation of a SDN architecture observer: detection of failure, distributed denial-of-service and unauthorized intrusion - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue Security and communication networks Année : 2023

Implementation of a SDN architecture observer: detection of failure, distributed denial-of-service and unauthorized intrusion

Thierry Divoux

Résumé

Software-defined networking was recently introduced and proposed to separate the control from the data plane. This architecture introduces new challenges, particularly with regard to security and safety. To address the safety challenges, it is necessary to set up a multi controller architecture to provide redundancy. In addition, the second controller can have a security benefit because it can be used to validate the decisions taken by the first controller. However, communication between the controllers is necessary in these architectures, which may be exploited by an attacker to spread across the controllers, resulting in a security issue. This study aims to develop a multi controller architecture without communication between controllers. The control is executed by the nominal controller, which performs the data plane computation, whereas the second controller is in charge of verifying the consistency of the controller's decisions, i.e., the management traffic. We first formulated the activity of the command and then provided conditions to determine a consistent control. These conditions include a time boundary, which corresponds to the tolerance for a delay in the response time of the controller, and structural properties to verify the consistency of the path setup. Moreover, we proposed a detection algorithm that is divided into two parts: first, a learning phase that aims to learn the consistent path set up by the controller, and second, a running phase which aims to verify that the controller sets up paths that are similar to the learned path. This algorithm was evaluated in terms of its reactivity, precision, and recall. To evaluate this, we considered three use cases: a distributed denial of service (DDOS) attack, an attack to send malicious packets on the network, and a failure of the controller.
Fichier principal
Vignette du fichier
Security_Comm_Hal.pdf (1.01 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03888497 , version 1 (07-12-2022)

Licence

Paternité

Identifiants

Citer

Loïc Desgeorges, Jean-Philippe Georges, Thierry Divoux. Implementation of a SDN architecture observer: detection of failure, distributed denial-of-service and unauthorized intrusion. Security and communication networks, 2023, 2023, pp.7244541. ⟨10.1155/2023/7244541⟩. ⟨hal-03888497⟩
53 Consultations
56 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More