Cargando…

Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks

For a Software Defined Network (SDN), security is an important factor affecting its large-scale deployment. The existing security solutions for SDN mainly focus on the controller itself, which has to handle all the security protection tasks by using the programmability of the network. This will undo...

Descripción completa

Detalles Bibliográficos
Autores principales: Lin, Zhaowen, Tao, Dan, Wang, Zhenji
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2017
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5426916/
https://www.ncbi.nlm.nih.gov/pubmed/28430155
http://dx.doi.org/10.3390/s17040920
_version_ 1783235579236843520
author Lin, Zhaowen
Tao, Dan
Wang, Zhenji
author_facet Lin, Zhaowen
Tao, Dan
Wang, Zhenji
author_sort Lin, Zhaowen
collection PubMed
description For a Software Defined Network (SDN), security is an important factor affecting its large-scale deployment. The existing security solutions for SDN mainly focus on the controller itself, which has to handle all the security protection tasks by using the programmability of the network. This will undoubtedly involve a heavy burden for the controller. More devastatingly, once the controller itself is attacked, the entire network will be paralyzed. Motivated by this, this paper proposes a novel security protection architecture for SDN. We design a security service orchestration center in the control plane of SDN, and this center physically decouples from the SDN controller and constructs SDN security services. We adopt virtualization technology to construct a security meta-function library, and propose a dynamic security service composition construction algorithm based on web service composition technology. The rule-combining method is used to combine security meta-functions to construct security services which meet the requirements of users. Moreover, the RETE algorithm is introduced to improve the efficiency of the rule-combining method. We evaluate our solutions in a realistic scenario based on OpenStack. Substantial experimental results demonstrate the effectiveness of our solutions that contribute to achieve the effective security protection with a small burden of the SDN controller.
format Online
Article
Text
id pubmed-5426916
institution National Center for Biotechnology Information
language English
publishDate 2017
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-54269162017-05-12 Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks Lin, Zhaowen Tao, Dan Wang, Zhenji Sensors (Basel) Article For a Software Defined Network (SDN), security is an important factor affecting its large-scale deployment. The existing security solutions for SDN mainly focus on the controller itself, which has to handle all the security protection tasks by using the programmability of the network. This will undoubtedly involve a heavy burden for the controller. More devastatingly, once the controller itself is attacked, the entire network will be paralyzed. Motivated by this, this paper proposes a novel security protection architecture for SDN. We design a security service orchestration center in the control plane of SDN, and this center physically decouples from the SDN controller and constructs SDN security services. We adopt virtualization technology to construct a security meta-function library, and propose a dynamic security service composition construction algorithm based on web service composition technology. The rule-combining method is used to combine security meta-functions to construct security services which meet the requirements of users. Moreover, the RETE algorithm is introduced to improve the efficiency of the rule-combining method. We evaluate our solutions in a realistic scenario based on OpenStack. Substantial experimental results demonstrate the effectiveness of our solutions that contribute to achieve the effective security protection with a small burden of the SDN controller. MDPI 2017-04-21 /pmc/articles/PMC5426916/ /pubmed/28430155 http://dx.doi.org/10.3390/s17040920 Text en © 2017 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Lin, Zhaowen
Tao, Dan
Wang, Zhenji
Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
title Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
title_full Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
title_fullStr Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
title_full_unstemmed Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
title_short Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
title_sort dynamic construction scheme for virtualization security service in software-defined networks
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5426916/
https://www.ncbi.nlm.nih.gov/pubmed/28430155
http://dx.doi.org/10.3390/s17040920
work_keys_str_mv AT linzhaowen dynamicconstructionschemeforvirtualizationsecurityserviceinsoftwaredefinednetworks
AT taodan dynamicconstructionschemeforvirtualizationsecurityserviceinsoftwaredefinednetworks
AT wangzhenji dynamicconstructionschemeforvirtualizationsecurityserviceinsoftwaredefinednetworks