Monshizadeh and Khatri
330
They also have disadvantages for mobile networks and therefore for TaaS:
● Centralized controller: potential for single attack;
● Vulnerable southbound interface (OpenFlow) between controller and data‐forwarding:
degrade network, availability, performance and integrity via DoS attack;
● Vulnerable northbound interface: between controller and applications;
● Programmability: applications have access to controller to program the network;
● Reduced isolation of network functions; and
● Expensive and vulnerable cryptographic keys.
SDN carries most of the three‐layer threats such as configuration, authorization and
access control, as well as software and images vulnerabilities. The Open Networking
Foundation (ONF) has identified the southbound interface between controllers and
data forwarding devices (SDN switches) as vulnerable. This interface uses OpenFlow
protocol, which could be vulnerable against spoofing if the authentication between
controllers and switches are not implemented correctly or is compromised [21].
Therefore, communication between controller and switch must be over the Transport
Layer Security (TLS) or IPSec, to avoid eavesdropping, tampering and DoS attacks at
the controller. Considering SDN, secure Application Programming Interface (API)
techniques must be utilized at the northbound interface.
Below are listed some of the monitoring, detection and prevention techniques that
could be used for SDN, NFV and OpenFlow security [21]:
• Sec App
• Virtual Network Element
Application
layer
Orchestrator
VM
Northbound
interface
OpenFlow
Southbound
interface
OpenFlow
Virtual
network
Virtual
network
Virtual
switch
Virtual
switch
Virtual
switch
Virtual
switch
Virtual
switch
Virtual
switch
• Monitoring app
• MME
VM
Infrastructure
layer
Virtual layer
OS
Control layer
SDN/SDM controller
Switches
Security
appliance
Figure 14.3 Layer‐based SDN architecture.
Précédent

- 372/483

Suivant