Ahmad, Liyanage, Shahabuddin, Ylianttila, and Gurtov
84
In SDN, network security functions can be implemented as applications deployed in
the SDN application plane. The applications gather traffic or network stats information
through the control plane from the data forwarding plane using the north‐bound interface (applications‐control plane API). For example a security application, such as an
intrusion detection application, can gather packet samples to perform analysis and then
direct the data forwarding plane through the control plane to either drop the packets or
forward the packets to a specific port. The port can be either towards the end user or a
security middle box for further analysis. This makes the security systems highly flexible.
When coupled with NFV, SDN would enable run‐time network security function placement at any network perimeter as the need arises. The other main benefit is the decoupling of the network security functions from vendor‐specific hardware. This decoupling
would allow the network operators to change the security functions whenever deemed
necessary, irrespective of the hardware specifications, or changes in the firmware of various hardware used for security purposes.
However, centralizing the network control and softwarizing network function opens
new security challenges. For example, the centralized control will be a favorable choice
for Denial of Service (DoS) attacks, and exposing the critical APIs to unintended software can render the whole network down. Some of the main threats are highlighted in
Table 4.1. Therefore, SDN‐based networks need novel security architectures right from
the beginning. Below, we highlight the main security threats in SDN‐based networks.
4.3.3 Security Challenges in SDN
4.3.3.1 Application Layer
SDN has two principle properties which form the foundation of networking innovation
on one hand and the basis of security challenges on the other. First, the ability to control a network by software, and second, centralization of network intelligence in
Network Administrator
Security Policies
Network Users
Data Path Elements
OF
switches
Traffic
Monitoring/
Security
MiddleBox
South-bound API (OpenFlow Protocol)
App-Specific API
Controller 3
Controller 2
Controller 1
SDN (OpenFlow) Controllers
North-bound API
SDN (OpenFlow) Applications
Traffic
Monitoring
Security
Policies
Intrusion
Detection
Security
MiddleBox
management
Authentication
& Authorization
Application Plane
Control Plane
Infrastructure Plane
Figure 4.3 An overview of the SDN architecture.
84
In SDN, network security functions can be implemented as applications deployed in
the SDN application plane. The applications gather traffic or network stats information
through the control plane from the data forwarding plane using the north‐bound interface (applications‐control plane API). For example a security application, such as an
intrusion detection application, can gather packet samples to perform analysis and then
direct the data forwarding plane through the control plane to either drop the packets or
forward the packets to a specific port. The port can be either towards the end user or a
security middle box for further analysis. This makes the security systems highly flexible.
When coupled with NFV, SDN would enable run‐time network security function placement at any network perimeter as the need arises. The other main benefit is the decoupling of the network security functions from vendor‐specific hardware. This decoupling
would allow the network operators to change the security functions whenever deemed
necessary, irrespective of the hardware specifications, or changes in the firmware of various hardware used for security purposes.
However, centralizing the network control and softwarizing network function opens
new security challenges. For example, the centralized control will be a favorable choice
for Denial of Service (DoS) attacks, and exposing the critical APIs to unintended software can render the whole network down. Some of the main threats are highlighted in
Table 4.1. Therefore, SDN‐based networks need novel security architectures right from
the beginning. Below, we highlight the main security threats in SDN‐based networks.
4.3.3 Security Challenges in SDN
4.3.3.1 Application Layer
SDN has two principle properties which form the foundation of networking innovation
on one hand and the basis of security challenges on the other. First, the ability to control a network by software, and second, centralization of network intelligence in
Network Administrator
Security Policies
Network Users
Data Path Elements
OF
switches
Traffic
Monitoring/
Security
MiddleBox
South-bound API (OpenFlow Protocol)
App-Specific API
Controller 3
Controller 2
Controller 1
SDN (OpenFlow) Controllers
North-bound API
SDN (OpenFlow) Applications
Traffic
Monitoring
Security
Policies
Intrusion
Detection
Security
MiddleBox
management
Authentication
& Authorization
Application Plane
Control Plane
Infrastructure Plane
Figure 4.3 An overview of the SDN architecture.
