Design Principles for 5G Security 85
network controllers [13]. Since most of the network functions can be implemented as
SDN applications, malicious applications, if not stopped early enough, can spread
havoc across a network. The main security challenges that applications can pose to the
network will be due to the availability of open APIs in network equipment, trust relationship between the controller and the applications (mainly third‐party applications)
and authentication and authorization of applications to change or modify the network
behavior [13]. In 5G most of the functionalities will be implemented as applications
due to the ease in modifications, making updates, and deployment. NFV will be the key
enabler of application‐based services and will take application‐based services into the
networking domains. Therefore, securing the network from anomalies generated by
applications will be highly important.
4.3.3.2 Controller Layer
In SDN the control plane (e.g. OpenFlow controller) is a centralized decision‐making
entity. Hence, the controller can be highly targeted for compromising the network or
carrying out malicious activities in the network due to its pivotal role. The same reason
is valid for DoS and DDoS attacks. Furthermore, malicious applications can acquire
network information from the controller if there are no compelling authentication and
authorization mechanisms in place in the controller. The visible nature of the controller
Table 4.1 Security challenges in SDN.
SDN Layer
Type of Threat
Threat Description
Application
Lack of authentication
and authorization
There are no compelling mechanisms for
authentication and authorization of applications,
and is more threatening in the case of a large
number of third‐party applications
Fraudulent rules
insertion
Malicious applications can generate false flow rules
Lack of access control
and accountability
A problem for the management plane and for illegal
usage of network resources
Control
DoS, DDoS attack
Due to the visible nature of the control plane
Unauthorized
controller access
No compelling mechanisms to obligate access
control for applications
Scalability or
availability
Centralizing intelligence in one entity will most
likely present scalability and availability challenges
Data Plane
Fraudulent flow rules
Data plane is dumb and hence more susceptible to
fraudulent flow rules
Flooding attacks
Flow tables of OpenFlow switches can store a finite
or limited number of flow rules
Controller hijacking
or compromise
Data Plane is dependent on the control plane,
making its security dependent on controller security
Ctrl‐Data Int.
TCP‐Level attacks
TLS is vulnerable to TCP‐level attacks
Man‐in‐the middle
attack
Optional use of TLS and complex configuration
of TLS
Précédent

- 127/483

Suivant