On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter

The widespread adoption and evolution of Software Defined Networking (SDN) have enabled the service providers to successfully simplify network management. Along with the traffic explosion, there is decreasing CAPEX and OPEX as well as an increase in the average revenue per user. However, this wide a...

Full description

Bibliographic Details
Main Authors: Ahmed Sallam, Ahmed Refaey, Abdallah Shami
Format: Article
Language:English
Published: IEEE 2019-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/8826550/
_version_ 1818665668744052736
author Ahmed Sallam
Ahmed Refaey
Abdallah Shami
author_facet Ahmed Sallam
Ahmed Refaey
Abdallah Shami
author_sort Ahmed Sallam
collection DOAJ
description The widespread adoption and evolution of Software Defined Networking (SDN) have enabled the service providers to successfully simplify network management. Along with the traffic explosion, there is decreasing CAPEX and OPEX as well as an increase in the average revenue per user. However, this wide adoption of SDNs is posing real challenges and concerns in terms of security aspects. The main challenges are how to provide proper authentication, access control, data privacy, and data integrity among others for the API-driven orchestration of network routing. Herein, the Software Defined Perimeter (SDP) is proposed as a framework to provide an orchestration of connections. The expectation is a framework that restricts network access and connections between objects on the SDN-enabled network infrastructures. There are several potential benefits as a result of the integration between SDP systems and SDNs. In particular, it provides a completely scalable and managed security solution. Consequently, it leads to flexible deployment that can be tailored to fit the need of any generic network security perimeter. The proposed Integrated frameworks are examined through virtualized network testbeds. The testing results demonstrate that the proposed framework is malleable to both port scanning (PS) attack and Denial of Service (DoS) bandwidth attack. In addition, it clarifies some interesting potential integration points between the SDP systems and SDNs to further research in this area.
first_indexed 2024-12-17T05:52:18Z
format Article
id doaj.art-138af3dd125e4da884a520d16e2a8a25
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-17T05:52:18Z
publishDate 2019-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-138af3dd125e4da884a520d16e2a8a252022-12-21T22:01:08ZengIEEEIEEE Access2169-35362019-01-01714657714658710.1109/ACCESS.2019.29397808826550On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined PerimeterAhmed Sallam0https://orcid.org/0000-0003-2807-2316Ahmed Refaey1https://orcid.org/0000-0002-1540-9349Abdallah Shami2Department of Electrical and Computer Engineering, Western University, London, ON, CanadaDepartment of Electrical and Computer Engineering, Western University, London, ON, CanadaDepartment of Electrical and Computer Engineering, Western University, London, ON, CanadaThe widespread adoption and evolution of Software Defined Networking (SDN) have enabled the service providers to successfully simplify network management. Along with the traffic explosion, there is decreasing CAPEX and OPEX as well as an increase in the average revenue per user. However, this wide adoption of SDNs is posing real challenges and concerns in terms of security aspects. The main challenges are how to provide proper authentication, access control, data privacy, and data integrity among others for the API-driven orchestration of network routing. Herein, the Software Defined Perimeter (SDP) is proposed as a framework to provide an orchestration of connections. The expectation is a framework that restricts network access and connections between objects on the SDN-enabled network infrastructures. There are several potential benefits as a result of the integration between SDP systems and SDNs. In particular, it provides a completely scalable and managed security solution. Consequently, it leads to flexible deployment that can be tailored to fit the need of any generic network security perimeter. The proposed Integrated frameworks are examined through virtualized network testbeds. The testing results demonstrate that the proposed framework is malleable to both port scanning (PS) attack and Denial of Service (DoS) bandwidth attack. In addition, it clarifies some interesting potential integration points between the SDP systems and SDNs to further research in this area.https://ieeexplore.ieee.org/document/8826550/SDPSDNDoS attacksecuritynetwork virtualization
spellingShingle Ahmed Sallam
Ahmed Refaey
Abdallah Shami
On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter
IEEE Access
SDP
SDN
DoS attack
security
network virtualization
title On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter
title_full On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter
title_fullStr On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter
title_full_unstemmed On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter
title_short On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter
title_sort on the security of sdn a completed secure and scalable framework using the software defined perimeter
topic SDP
SDN
DoS attack
security
network virtualization
url https://ieeexplore.ieee.org/document/8826550/
work_keys_str_mv AT ahmedsallam onthesecurityofsdnacompletedsecureandscalableframeworkusingthesoftwaredefinedperimeter
AT ahmedrefaey onthesecurityofsdnacompletedsecureandscalableframeworkusingthesoftwaredefinedperimeter
AT abdallahshami onthesecurityofsdnacompletedsecureandscalableframeworkusingthesoftwaredefinedperimeter