Security analysis in heterogeneous fault-tolerant control plane

Qi WU,Hongchang CHEN,Fucai CHEN   

  1. National Digital Switching System Engineering and Technological R&D Center,Zhengzhou 450001,China
    The National Key R&D Program of China(2016YFB0800101)


With the large-scale application of software-defined networks,the security of software-defined networks becomes more and more important.As an important defense idea,the fault-tolerant control plane based on heterogeneity has attracted more and more researchers' attention in recent years.However,the existing researches ignore the problem of common vulnerability in heterogeneous variants,which greatly reduces the security benefits of the fault-tolerant control architecture for software-defined networks.Addressing this problem,the common vulnerability was taken in heterogeneous variants into considerations.First,the tolerance capability of the fault-tolerant control plane was quantified.Then a control plane deployment method was constructed which was able to maximize the tolerance capability.The simulations show that the proposed method can effectively reduce the failure probability of the control plane.When the attackers attack the control plane constructed based on the proposed method,they pay more attack cost to compromise the control plane.

Key words: software-defined network, common vulnerability, heterogeneous variant, tolerance capability

