Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification
Abstract Software-defined networking (SDN) has significantly transformed the field of network management through the consolidation of control and provision of enhanced adaptability. However, this paradigm shift has concurrently presented novel security concerns. The preservation of service path inte...
Main Authors: | , , , , , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
Nature Portfolio
2023-10-01
|
Series: | Scientific Reports |
Online Access: | https://doi.org/10.1038/s41598-023-44701-7 |
_version_ | 1827711290994327552 |
---|---|
author | S. Pradeep Yogesh Kumar Sharma Umesh Kumar Lilhore Sarita Simaiya Abhishek Kumar Sachin Ahuja Martin Margala Prasun Chakrabarti Tulika Chakrabarti |
author_facet | S. Pradeep Yogesh Kumar Sharma Umesh Kumar Lilhore Sarita Simaiya Abhishek Kumar Sachin Ahuja Martin Margala Prasun Chakrabarti Tulika Chakrabarti |
author_sort | S. Pradeep |
collection | DOAJ |
description | Abstract Software-defined networking (SDN) has significantly transformed the field of network management through the consolidation of control and provision of enhanced adaptability. However, this paradigm shift has concurrently presented novel security concerns. The preservation of service path integrity holds significant importance within SDN environments due to the potential for malevolent entities to exploit network flows, resulting in a range of security breaches. This research paper introduces a model called "EnsureS", which aims to enhance the security of SDN by proposing an efficient and secure service path validation approach. The proposed approach utilizes a Lightweight Service Path Validation using Batch Hashing and Tag Verification, focusing on improving service path validation's efficiency and security in SDN environments. The proposed EnsureS system utilizes two primary techniques in order to validate service pathways efficiently. Firstly, the method utilizes batch hashing in order to minimize computational overhead. The proposed EnsureS algorithm enhances performance by aggregating packets through batches rather than independently; the hashing process takes place on each one in the service pathway. Additionally, the implementation of tag verification enables network devices to efficiently verify the authenticity of packets by leveraging pre-established trust relationships. EnsureS provides a streamlined and effective approach for validating service paths in SDN environments by integrating these methodologies. In order to assess the efficacy of the Proposed EnsureS, a comprehensive series of investigations were conducted within a simulated SDN circumstance. The efficacy of Proposed EnsureS was then compared to that of established methods. The findings of our study indicate that the proposed EnsureS solution effectively minimizes computational overhead without compromising on the established security standards. The implementation successfully reduces the impact of different types of attacks, such as route alteration and packet spoofing, increasing SDN networks' general integrity. |
first_indexed | 2024-03-10T17:53:37Z |
format | Article |
id | doaj.art-30934f7877ab458ea414c4d67cdb863d |
institution | Directory Open Access Journal |
issn | 2045-2322 |
language | English |
last_indexed | 2024-03-10T17:53:37Z |
publishDate | 2023-10-01 |
publisher | Nature Portfolio |
record_format | Article |
series | Scientific Reports |
spelling | doaj.art-30934f7877ab458ea414c4d67cdb863d2023-11-20T09:16:50ZengNature PortfolioScientific Reports2045-23222023-10-0113111310.1038/s41598-023-44701-7Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verificationS. Pradeep0Yogesh Kumar Sharma1Umesh Kumar Lilhore2Sarita Simaiya3Abhishek Kumar4Sachin Ahuja5Martin Margala6Prasun Chakrabarti7Tulika Chakrabarti8Department of Computer Science and Engineering, Malla Reddy Engineering College for Women, UGC Autonomous InstitutionDepartment of Computer Science and Engineering, Koneru Lakshmaiah Education FoundationDepartment of Computer Science and Engineering, Chandigarh UniversityAPEX Institute of Technology (AIT), CSE, Chandigarh UniversityDepartment of Computer Science and Engineering, Chandigarh UniversityDepartment of Computer Science and Engineering, Chandigarh UniversitySchool of Computing, University of Louisiana at LafayetteSir Padampat, Singhania UniversitySir Padampat, Singhania UniversityAbstract Software-defined networking (SDN) has significantly transformed the field of network management through the consolidation of control and provision of enhanced adaptability. However, this paradigm shift has concurrently presented novel security concerns. The preservation of service path integrity holds significant importance within SDN environments due to the potential for malevolent entities to exploit network flows, resulting in a range of security breaches. This research paper introduces a model called "EnsureS", which aims to enhance the security of SDN by proposing an efficient and secure service path validation approach. The proposed approach utilizes a Lightweight Service Path Validation using Batch Hashing and Tag Verification, focusing on improving service path validation's efficiency and security in SDN environments. The proposed EnsureS system utilizes two primary techniques in order to validate service pathways efficiently. Firstly, the method utilizes batch hashing in order to minimize computational overhead. The proposed EnsureS algorithm enhances performance by aggregating packets through batches rather than independently; the hashing process takes place on each one in the service pathway. Additionally, the implementation of tag verification enables network devices to efficiently verify the authenticity of packets by leveraging pre-established trust relationships. EnsureS provides a streamlined and effective approach for validating service paths in SDN environments by integrating these methodologies. In order to assess the efficacy of the Proposed EnsureS, a comprehensive series of investigations were conducted within a simulated SDN circumstance. The efficacy of Proposed EnsureS was then compared to that of established methods. The findings of our study indicate that the proposed EnsureS solution effectively minimizes computational overhead without compromising on the established security standards. The implementation successfully reduces the impact of different types of attacks, such as route alteration and packet spoofing, increasing SDN networks' general integrity.https://doi.org/10.1038/s41598-023-44701-7 |
spellingShingle | S. Pradeep Yogesh Kumar Sharma Umesh Kumar Lilhore Sarita Simaiya Abhishek Kumar Sachin Ahuja Martin Margala Prasun Chakrabarti Tulika Chakrabarti Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification Scientific Reports |
title | Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification |
title_full | Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification |
title_fullStr | Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification |
title_full_unstemmed | Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification |
title_short | Developing an SDN security model (EnsureS) based on lightweight service path validation with batch hashing and tag verification |
title_sort | developing an sdn security model ensures based on lightweight service path validation with batch hashing and tag verification |
url | https://doi.org/10.1038/s41598-023-44701-7 |
work_keys_str_mv | AT spradeep developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification AT yogeshkumarsharma developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification AT umeshkumarlilhore developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification AT saritasimaiya developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification AT abhishekkumar developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification AT sachinahuja developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification AT martinmargala developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification AT prasunchakrabarti developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification AT tulikachakrabarti developingansdnsecuritymodelensuresbasedonlightweightservicepathvalidationwithbatchhashingandtagverification |