Ahmad, Liyanage, Shahabuddin, Ylianttila, and Gurtov
88
4.4 Security in SDN‐based Mobile Networks
The current version of SDN, that is the OpenFlow, operates on traffic flows. A flow can
be a number of packets with the same characteristics, for example same TCP connection, or packets with a particular MAC or IP address. Operating on flows has been
shown to be much more feasible in terms of control and granularity. The basic operation on flows is such that OpenFlow has three main entities as explained for the concept
of SDN. These are:
1) OpenFlow applications: SDN application plane;
2) OpenFlow controllers: the SDN control plane; and
3) OpenFlow Switches: the SDN data plane.
The OpenFlow switches are dumb data path elements that forward packets between
ports based on the instructions installed in their flow tables by the controller. The
OpenFlow switch has three basic elements:
1) a flow table with actions associated with each flow;
2) a secure channel to the controller; using
3) an OpenFlow protocol that provides an open and standard mechanism for the
controller to communicate with the switch [22,23].
When a new flow arrives, the switch checks its flow table for a matching entry. If there
is no matching entry, the switch forwards it to the controller. The controller installs a
matching entry in the switch flow table. Henceforth, when flows arrive at the switch,
the switch checks its flow tables and acts accordingly. The flow tables have basically three
types of actions for the packets. First, forward the flow to a given port as enlisted in the
matching flow entry in the table. Second, encapsulate and forward the flow to the controller. Third, drop the flow’s packets. This makes security services rather simple in SDN
and forms the basis of security in future technologies:
● Flow sampling: is the selection of packets or packet header fields through various
algorithms for analysis. Selected samples can be sent to security applications or
systems to analyze the content of the flow and verify security threats or vulnerabilities. Basic analysis targets can be the content of the flow packets or header fields,
frequency of particular types of packets, and inter‐arrival times of packets with
different characteristics. In SDNs, flow sampling can be as easy as changing the
output port numbers and counters in the flow tables of the switch. The destination
on that port can be a security system and the counter can show the number of
packets to be sent to that destination.
In the following sections, we elaborate how the concepts of SDN can be used to provide
robust security for mobile networks.
4.4.1 Data Link Security
Data link security is necessary to ensure that the data flows between the authorized end‐
points and is not diverted or intercepted while in transit. The previous generations, that
is, 3G and 4G, did not provide cryptographic integrity to user plane communication. In
5G, it will be a major security concern and will expose private communication not only
88
4.4 Security in SDN‐based Mobile Networks
The current version of SDN, that is the OpenFlow, operates on traffic flows. A flow can
be a number of packets with the same characteristics, for example same TCP connection, or packets with a particular MAC or IP address. Operating on flows has been
shown to be much more feasible in terms of control and granularity. The basic operation on flows is such that OpenFlow has three main entities as explained for the concept
of SDN. These are:
1) OpenFlow applications: SDN application plane;
2) OpenFlow controllers: the SDN control plane; and
3) OpenFlow Switches: the SDN data plane.
The OpenFlow switches are dumb data path elements that forward packets between
ports based on the instructions installed in their flow tables by the controller. The
OpenFlow switch has three basic elements:
1) a flow table with actions associated with each flow;
2) a secure channel to the controller; using
3) an OpenFlow protocol that provides an open and standard mechanism for the
controller to communicate with the switch [22,23].
When a new flow arrives, the switch checks its flow table for a matching entry. If there
is no matching entry, the switch forwards it to the controller. The controller installs a
matching entry in the switch flow table. Henceforth, when flows arrive at the switch,
the switch checks its flow tables and acts accordingly. The flow tables have basically three
types of actions for the packets. First, forward the flow to a given port as enlisted in the
matching flow entry in the table. Second, encapsulate and forward the flow to the controller. Third, drop the flow’s packets. This makes security services rather simple in SDN
and forms the basis of security in future technologies:
● Flow sampling: is the selection of packets or packet header fields through various
algorithms for analysis. Selected samples can be sent to security applications or
systems to analyze the content of the flow and verify security threats or vulnerabilities. Basic analysis targets can be the content of the flow packets or header fields,
frequency of particular types of packets, and inter‐arrival times of packets with
different characteristics. In SDNs, flow sampling can be as easy as changing the
output port numbers and counters in the flow tables of the switch. The destination
on that port can be a security system and the counter can show the number of
packets to be sent to that destination.
In the following sections, we elaborate how the concepts of SDN can be used to provide
robust security for mobile networks.
4.4.1 Data Link Security
Data link security is necessary to ensure that the data flows between the authorized end‐
points and is not diverted or intercepted while in transit. The previous generations, that
is, 3G and 4G, did not provide cryptographic integrity to user plane communication. In
5G, it will be a major security concern and will expose private communication not only
