DPSec: A blockchain-based data plane authentication protocol for SDNs

Majd Latah, Kübra Kalkan
{"title":"DPSec: A blockchain-based data plane authentication protocol for SDNs","authors":"Majd Latah, Kübra Kalkan","doi":"10.1109/BCCA50787.2020.9274449","DOIUrl":null,"url":null,"abstract":"Software-Defined Networking (SDN) is a promising networking architecture that enables central management along with network programmability. However, SDN brings additional security threats due to untrusted control and data planes. In this work, we focus on authenticating SDN’s data plane since it can be exploited to attack SDN’s control plane. As a result, the whole SDN network will be paralysed. On the other hand, Blockchain (BC) can be utilized to provide more secure data plane by introducing a fault-tolerant, decentralized and secure ledger without relying on any trusted third-party intermediaries. To this end, in this work we propose, DPSec, a consortium BC-based protocol for authenticating SDN’s data plane including SDN switches and hosts. We also provide a proof-of-concept that demonstrates the applicability and feasibility of our protocol in SDNs. Finally, we present a security analysis that shows how DPSec can address several attacks against SDNs including CVE-2018-1000155 vulnerability [1] that targets SDN controllers due to the untrusted data plane.","PeriodicalId":218474,"journal":{"name":"2020 Second International Conference on Blockchain Computing and Applications (BCCA)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2020-11-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 Second International Conference on Blockchain Computing and Applications (BCCA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BCCA50787.2020.9274449","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Software-Defined Networking (SDN) is a promising networking architecture that enables central management along with network programmability. However, SDN brings additional security threats due to untrusted control and data planes. In this work, we focus on authenticating SDN’s data plane since it can be exploited to attack SDN’s control plane. As a result, the whole SDN network will be paralysed. On the other hand, Blockchain (BC) can be utilized to provide more secure data plane by introducing a fault-tolerant, decentralized and secure ledger without relying on any trusted third-party intermediaries. To this end, in this work we propose, DPSec, a consortium BC-based protocol for authenticating SDN’s data plane including SDN switches and hosts. We also provide a proof-of-concept that demonstrates the applicability and feasibility of our protocol in SDNs. Finally, we present a security analysis that shows how DPSec can address several attacks against SDNs including CVE-2018-1000155 vulnerability [1] that targets SDN controllers due to the untrusted data plane.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
DPSec:基于区块链的sdn数据平面认证协议
软件定义网络(SDN)是一种很有前途的网络体系结构,它支持集中管理和网络可编程性。但是,SDN由于不可信的控制和数据平面带来了额外的安全威胁。在这项工作中,我们重点关注SDN的数据平面的认证,因为它可以被利用来攻击SDN的控制平面。这将导致整个SDN网络瘫痪。另一方面,区块链(BC)可以在不依赖任何可信第三方中介的情况下,通过引入容错、分散和安全的分类账,提供更安全的数据平面。为此,在这项工作中,我们提出了DPSec,这是一个基于联盟bc的协议,用于验证SDN的数据平面,包括SDN交换机和主机。我们还提供了一个概念验证,证明了我们的协议在sdn中的适用性和可行性。最后,我们提出了一个安全分析,展示了DPSec如何解决针对SDN的几种攻击,包括CVE-2018-1000155漏洞[1],该漏洞针对SDN控制器,由于不受信任的数据平面。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Coordinated Landmark-based Routing for Blockchain Offline Channels A Blockchain Based Decentralized Computing And NFT Infrastructure For Game Networks Improving the performance of the Proof-of-Work Consensus Protocol Using Machine learning OraclesLink: An architecture for secure oracle usage BCCA 2020 Preface
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1