Software-Defined Network (SDN) Data Plane Security: Issues, Solutions and Future Directions

Arash Shaghaghi,Mohamed Ali Kaafar,Rajkumar Buyya,Sanjay Jha
DOI: https://doi.org/10.48550/arXiv.1804.00262
2018-04-01
Abstract:Software-Defined Network (SDN) radically changes the network architecture by decoupling the network logic from the underlying forwarding devices. This architectural change rejuvenates the network-layer granting centralized management and re-programmability of the networks. From a security perspective, SDN separates security concerns into control and data plane, and this architectural recomposition brings up exciting opportunities and challenges. The overall perception is that SDN capabilities will ultimately result in improved security. However, in its raw form, SDN could potentially make networks more vulnerable to attacks and harder to protect. In this paper, we focus on identifying challenges faced in securing the data plane of SDN - one of the least explored but most critical components of this technology. We formalize this problem space, identify potential attack scenarios while highlighting possible vulnerabilities and establish a set of requirements and challenges to protect the data plane of SDNs. Moreover, we undertake a survey of existing solutions with respect to the identified threats, identifying their limitations and offer future research directions.
Cryptography and Security
What problem does this paper attempt to address?
The problem that this paper attempts to solve is the security challenges in the software - defined networking (SDN) data plane. Specifically, the author focuses on how the data plane, as one of the most critical but least - studied components in the SDN architecture, faces security threats in the SDN architecture and the potential vulnerabilities that these threats may bring. The paper aims to systematically analyze and solve these problems by identifying attack scenarios, clarifying potential vulnerabilities, and proposing a set of requirements and challenges for protecting the SDN data plane. In addition, the paper also reviews the existing solutions, points out their limitations, and proposes future research directions.