Amar Almaini
Delegation of Authentication to the Data Plane in Software-Defined Networks
Almaini, Amar; Al-Dubai, Ahmed; Romdhani, Imed; Schramm, Martin
Authors
Prof Ahmed Al-Dubai A.Al-Dubai@napier.ac.uk
Professor
Dr Imed Romdhani I.Romdhani@napier.ac.uk
Associate Professor
Martin Schramm
Abstract
OpenFlow is considered as the most known protocol for Software Defined Networking (SDN). The main drawback of OpenFlow is the lack of support of new header definitions, which is required by network operators to apply new packet encapsulations. While SDN's logically centralized control plane could enhance network security by providing global visibility of the network state, it still has many side effects. The intelligent controllers that orchestrate the dumb switches are overloaded and become prone to failure. Delegating some level of control logic to the switches can offload the controllers from local state based decisions that do not require global network-wide knowledge. Thus, this paper, to the best of our knowledge, is the first to propose the delegation of typical security functions from specialized middleboxes to the data plane. We leverage the opportunities offered by P4 language to implement the functionality of authenticating nodes using port knocking. Our experimental results indicate that our proposed technique improves the network overall availability by offloading the controller as well as reducing the traffic in the network without noticeable negative impact on switches' performance.
Citation
Almaini, A., Al-Dubai, A., Romdhani, I., & Schramm, M. (2019, October). Delegation of Authentication to the Data Plane in Software-Defined Networks. Presented at 2019 IEEE International Conferences on Ubiquitous Computing & Communications (IUCC) and Data Science and Computational Intelligence (DSCI) and Smart Computing, Networking and Services (SmartCNS), Shenyang, China
Presentation Conference Type | Conference Paper (Published) |
---|---|
Conference Name | 2019 IEEE International Conferences on Ubiquitous Computing & Communications (IUCC) and Data Science and Computational Intelligence (DSCI) and Smart Computing, Networking and Services (SmartCNS) |
Start Date | Oct 21, 2019 |
End Date | Oct 23, 2019 |
Acceptance Date | Oct 1, 2019 |
Online Publication Date | Feb 6, 2020 |
Publication Date | Feb 6, 2020 |
Deposit Date | Feb 24, 2020 |
Publisher | Institute of Electrical and Electronics Engineers |
Pages | 58-65 |
Book Title | 2019 IEEE International Conferences on Ubiquitous Computing & Communications (IUCC) and Data Science and Computational Intelligence (DSCI) and Smart Computing, Networking and Services (SmartCNS) |
ISBN | 9781728152097 |
DOI | https://doi.org/10.1109/iucc/dsci/smartcns.2019.00038 |
Keywords | Software-Defined Networking (SDN), data plane programmability, port scan, security, P4 |
Public URL | http://researchrepository.napier.ac.uk/Output/2584822 |
You might also like
Password Pattern and Vulnerability Analysis for Web and Mobile Applications
(2016)
Journal Article
Distributed and compressed MIKEY mode to secure end-to-end communications in the Internet of things
(2016)
Presentation / Conference Contribution
A new dynamic weight clustering algorithm for wireless sensor networks
(2017)
Presentation / Conference Contribution
A new distributed MIKEY mode to secure e-health applications.
(2016)
Presentation / Conference Contribution
Downloadable Citations
About Edinburgh Napier Research Repository
Administrator e-mail: repository@napier.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2024
Advanced Search