Design Principles for 5G Security 87
packet characteristics to implement new security services. Therefore, various solutions
are proposed to enable the applications work in its functional boundaries with controlled access to network resources. The PermOF is a fine‐grained permission system
that provides controlled access of data and control planes to the SDN applications. The
design of PermOF provides read, notification, write and system permissions to various
applications to enforce permission control.
The NGMN security recommendation advises application level data integrity
protection for battery constrained IoT devices or low latency 5G devices for user plane
data integrity. This will enable data protection beyond the mobile network, thus minimizing the chances of vulnerability of data due to compromises in the network. Thus,
SDN enables such applications to implement end‐to‐end security for constrained
devices beyond the security implications of the network.
4.3.4.2 Control Plane Security
Since the security of the control plane is pivotal to the whole network, there have been
many proposals and approaches for securing the control plane. The Security‐Enhanced
(SE) Floodlight controller [19] is an extended and secure version of the original floodlight controller [20]. By securing the SDN control layer, the SE‐Floodlight controller
provides mechanisms for privilege separation by adding a secure programmable north‐
bound API to the controller and operates as a mediator between the application and
data planes. It verifies flow rules generated by applications and attempts to resolve flow
rules conflicts between applications.
To mitigate the risks of controller failure due to scalability, or the chances of DoS
attacks due to its centralized role, controller resilience strategies have been proposed. The strategies include controller resilience through redundancy, maximizing
its storage and processing capabilities, and distributing controller functionalities
among multiple control points in the network. The OpenFlow variant of SDN supports wildcard rules so that the controller sends an aggregate of client requests to
server replicas. By default, microflow requests are handled by the controller that can
create potential scalability challenges and increase the chances of failures due to DoS
attacks. Normally reactive controllers are used that act on a flow request when it
arrives at the controller. Proactive controllers would install the flow rules in advance,
thus minimizing the flow request queue in the controller. Similarly, various load
balancing techniques are suggested that will balance the load among multiple
controllers in a network.
4.3.4.3 Data Plane Security Solutions
The data plane that transports the actual packets also requires proper security mechanisms. The data plane must be secured from unauthorized applications. Applications
can install, change or modify flow rules in the data plane, therefore security mechanisms
such as authentication and authorization are used for applications that can change the
flow rules in the data plane. FortNox [21] enables the controller to check contradictions
in flow rules generated by applications. FlowCchecker [22] identifies inconsistencies in
the flow rules in the data plane switches. Multiple controllers proposed for the controller
resilience also help the data plane elements work if one controller fails to provide flow
rules for newly arrived traffic flows.
Précédent

- 129/483

Suivant