Ahmad, Liyanage, Shahabuddin, Ylianttila, and Gurtov
86
makes it a favorite choice for DoS attacks. Since the SDN controller modifies flow rules
in the data path, the controller traffic can be easily identified, thus making the controller
a visible entity in the network. Scalability of the controller is another challenge that can
be targeted to make the controller a bottleneck for the whole network. If the number of
controllers is less or the controller capabilities are not good enough to respond to the
queries of the data path elements, the controller can easily become a bottleneck [17].
4.3.3.3 Infrastructure Layer
The SDN switches have flow tables used by the controller to install flow rules for each
flow. If the number of flows increases in the switch, there is a high chance that the flow
tables will be exhausted. Thus, malicious users can send flows with different field headers making the flow tables to exhaust to cause saturation attacks. In this case, legitimate
flows will be discarded due to the limited capability of the switch to buffer legitimate
TCP/UDP flows. Since the switches are dumb by taking intelligence to the control plane,
it will not be possible for the switches to differentiate genuine flows from the malicious
ones. Therefore, the switch can be used for attacks against other switches and the controller. Furthermore, the data plane is dependent on the security of the control plane. If
the security of the controller is compromised so that it does not provide instructions for
the incoming flows, the data plane will be practically offline. This also makes the controller‐data plane link a favorable choice for attacks. Transport Layer Security (TLS) and
Datagram Transport Layer Security (DTLS) are specified for the controller‐switch communication. However, the use of TLS and DTLS are left optional mainly due to its configuration complexity. This leaves the controller‐switch communication open to attacks,
thus increasing the vulnerability of the data and control planes.
4.3.4 Security Solutions for SDN
The logically centralized control plane of SDN provides a global view of the network and
enables run‐time configuration of the network elements. As a result, the SDN architecture supports highly reactive and proactive security monitoring, traffic analysis and
response systems to facilitate network forensics, alteration of security policies and security service insertion [18]. SDN facilitates quick threat identification through a cycle of
harvesting intelligence from the network resources, states and flows. The SDN architecture supports traffic redirection through flow‐tables modification to analyze the
data, update the policy, and reprogram the network accordingly. The programmability
achieved by SDNs facilitates dynamic security policy alteration without the need of individual hardware configuration. The automation, thus achieved, would reduce the chances
of misconfiguration and policy conflicts across different networks. Consistent network
security policies can be deployed across the network due to the global network visibility,
whereas security services such as firewalls and Intrusion Detection Systems (IDS) can
be deployed on specified traffic according to globally defined security policies.
Below, we define the security of each plane or layer of SDN.
4.3.4.1 Application Plane Security
The SDN control plane works between the network hardware and applications to hide
the network complexity from applications. Hence, the centralized control architecture
makes it easy to use applications by providing them with the network statistics and
86
makes it a favorite choice for DoS attacks. Since the SDN controller modifies flow rules
in the data path, the controller traffic can be easily identified, thus making the controller
a visible entity in the network. Scalability of the controller is another challenge that can
be targeted to make the controller a bottleneck for the whole network. If the number of
controllers is less or the controller capabilities are not good enough to respond to the
queries of the data path elements, the controller can easily become a bottleneck [17].
4.3.3.3 Infrastructure Layer
The SDN switches have flow tables used by the controller to install flow rules for each
flow. If the number of flows increases in the switch, there is a high chance that the flow
tables will be exhausted. Thus, malicious users can send flows with different field headers making the flow tables to exhaust to cause saturation attacks. In this case, legitimate
flows will be discarded due to the limited capability of the switch to buffer legitimate
TCP/UDP flows. Since the switches are dumb by taking intelligence to the control plane,
it will not be possible for the switches to differentiate genuine flows from the malicious
ones. Therefore, the switch can be used for attacks against other switches and the controller. Furthermore, the data plane is dependent on the security of the control plane. If
the security of the controller is compromised so that it does not provide instructions for
the incoming flows, the data plane will be practically offline. This also makes the controller‐data plane link a favorable choice for attacks. Transport Layer Security (TLS) and
Datagram Transport Layer Security (DTLS) are specified for the controller‐switch communication. However, the use of TLS and DTLS are left optional mainly due to its configuration complexity. This leaves the controller‐switch communication open to attacks,
thus increasing the vulnerability of the data and control planes.
4.3.4 Security Solutions for SDN
The logically centralized control plane of SDN provides a global view of the network and
enables run‐time configuration of the network elements. As a result, the SDN architecture supports highly reactive and proactive security monitoring, traffic analysis and
response systems to facilitate network forensics, alteration of security policies and security service insertion [18]. SDN facilitates quick threat identification through a cycle of
harvesting intelligence from the network resources, states and flows. The SDN architecture supports traffic redirection through flow‐tables modification to analyze the
data, update the policy, and reprogram the network accordingly. The programmability
achieved by SDNs facilitates dynamic security policy alteration without the need of individual hardware configuration. The automation, thus achieved, would reduce the chances
of misconfiguration and policy conflicts across different networks. Consistent network
security policies can be deployed across the network due to the global network visibility,
whereas security services such as firewalls and Intrusion Detection Systems (IDS) can
be deployed on specified traffic according to globally defined security policies.
Below, we define the security of each plane or layer of SDN.
4.3.4.1 Application Plane Security
The SDN control plane works between the network hardware and applications to hide
the network complexity from applications. Hence, the centralized control architecture
makes it easy to use applications by providing them with the network statistics and
