Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification

Abstract Software-defined networking (SDN) has significantly transformed the field of network management through the consolidation of control and provision of enhanced adaptability. However, this paradigm shift has concurrently presented novel security concerns. The preservation of service path inte...

Full description

Bibliographic Details
Main Authors: S. Pradeep, Yogesh Kumar Sharma, Umesh Kumar Lilhore, Sarita Simaiya, Abhishek Kumar, Sachin Ahuja, Martin Margala, Prasun Chakrabarti, Tulika Chakrabarti
Format: Article
Language:English
Published: Nature Portfolio 2023-10-01
Series:Scientific Reports
Online Access:https://doi.org/10.1038/s41598-023-44701-7
_version_ 1827711290994327552
author S. Pradeep
Yogesh Kumar Sharma
Umesh Kumar Lilhore
Sarita Simaiya
Abhishek Kumar
Sachin Ahuja
Martin Margala
Prasun Chakrabarti
Tulika Chakrabarti
author_facet S. Pradeep
Yogesh Kumar Sharma
Umesh Kumar Lilhore
Sarita Simaiya
Abhishek Kumar
Sachin Ahuja
Martin Margala
Prasun Chakrabarti
Tulika Chakrabarti
author_sort S. Pradeep
collection DOAJ
description Abstract Software-defined networking (SDN) has significantly transformed the field of network management through the consolidation of control and provision of enhanced adaptability. However, this paradigm shift has concurrently presented novel security concerns. The preservation of service path integrity holds significant importance within SDN environments due to the potential for malevolent entities to exploit network flows, resulting in a range of security breaches. This research paper introduces a model called "EnsureS", which aims to enhance the security of SDN by proposing an efficient and secure service path validation approach. The proposed approach utilizes a Lightweight Service Path Validation using Batch Hashing and Tag Verification, focusing on improving service path validation's efficiency and security in SDN environments. The proposed EnsureS system utilizes two primary techniques in order to validate service pathways efficiently. Firstly, the method utilizes batch hashing in order to minimize computational overhead. The proposed EnsureS algorithm enhances performance by aggregating packets through batches rather than independently; the hashing process takes place on each one in the service pathway. Additionally, the implementation of tag verification enables network devices to efficiently verify the authenticity of packets by leveraging pre-established trust relationships. EnsureS provides a streamlined and effective approach for validating service paths in SDN environments by integrating these methodologies. In order to assess the efficacy of the Proposed EnsureS, a comprehensive series of investigations were conducted within a simulated SDN circumstance. The efficacy of Proposed EnsureS was then compared to that of established methods. The findings of our study indicate that the proposed EnsureS solution effectively minimizes computational overhead without compromising on the established security standards. The implementation successfully reduces the impact of different types of attacks, such as route alteration and packet spoofing, increasing SDN networks' general integrity.
first_indexed 2024-03-10T17:53:37Z
format Article
id doaj.art-30934f7877ab458ea414c4d67cdb863d
institution Directory Open Access Journal
issn 2045-2322
language English
last_indexed 2024-03-10T17:53:37Z
publishDate 2023-10-01
publisher Nature Portfolio
record_format Article
series Scientific Reports
spelling doaj.art-30934f7877ab458ea414c4d67cdb863d2023-11-20T09:16:50ZengNature PortfolioScientific Reports2045-23222023-10-0113111310.1038/s41598-023-44701-7Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verificationS. Pradeep0Yogesh Kumar Sharma1Umesh Kumar Lilhore2Sarita Simaiya3Abhishek Kumar4Sachin Ahuja5Martin Margala6Prasun Chakrabarti7Tulika Chakrabarti8Department of Computer Science and Engineering, Malla Reddy Engineering College for Women, UGC Autonomous InstitutionDepartment of Computer Science and Engineering, Koneru Lakshmaiah Education FoundationDepartment of Computer Science and Engineering, Chandigarh UniversityAPEX Institute of Technology (AIT), CSE, Chandigarh UniversityDepartment of Computer Science and Engineering, Chandigarh UniversityDepartment of Computer Science and Engineering, Chandigarh UniversitySchool of Computing, University of Louisiana at LafayetteSir Padampat, Singhania UniversitySir Padampat, Singhania UniversityAbstract Software-defined networking (SDN) has significantly transformed the field of network management through the consolidation of control and provision of enhanced adaptability. However, this paradigm shift has concurrently presented novel security concerns. The preservation of service path integrity holds significant importance within SDN environments due to the potential for malevolent entities to exploit network flows, resulting in a range of security breaches. This research paper introduces a model called "EnsureS", which aims to enhance the security of SDN by proposing an efficient and secure service path validation approach. The proposed approach utilizes a Lightweight Service Path Validation using Batch Hashing and Tag Verification, focusing on improving service path validation's efficiency and security in SDN environments. The proposed EnsureS system utilizes two primary techniques in order to validate service pathways efficiently. Firstly, the method utilizes batch hashing in order to minimize computational overhead. The proposed EnsureS algorithm enhances performance by aggregating packets through batches rather than independently; the hashing process takes place on each one in the service pathway. Additionally, the implementation of tag verification enables network devices to efficiently verify the authenticity of packets by leveraging pre-established trust relationships. EnsureS provides a streamlined and effective approach for validating service paths in SDN environments by integrating these methodologies. In order to assess the efficacy of the Proposed EnsureS, a comprehensive series of investigations were conducted within a simulated SDN circumstance. The efficacy of Proposed EnsureS was then compared to that of established methods. The findings of our study indicate that the proposed EnsureS solution effectively minimizes computational overhead without compromising on the established security standards. The implementation successfully reduces the impact of different types of attacks, such as route alteration and packet spoofing, increasing SDN networks' general integrity.https://doi.org/10.1038/s41598-023-44701-7
spellingShingle S. Pradeep
Yogesh Kumar Sharma
Umesh Kumar Lilhore
Sarita Simaiya
Abhishek Kumar
Sachin Ahuja
Martin Margala
Prasun Chakrabarti
Tulika Chakrabarti
Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification
Scientific Reports
title Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification
title_full Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification
title_fullStr Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification
title_full_unstemmed Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification
title_short Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification
title_sort developing an sdn security model ensures based on lightweight service path validation with batch hashing and tag verification
url https://doi.org/10.1038/s41598-023-44701-7
work_keys_str_mv AT spradeep developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification
AT yogeshkumarsharma developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification
AT umeshkumarlilhore developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification
AT saritasimaiya developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification
AT abhishekkumar developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification
AT sachinahuja developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification
AT martinmargala developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification
AT prasunchakrabarti developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification
AT tulikachakrabarti developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification