Chinese Journal of Network and Information Security ›› 2017, Vol. 3 ›› Issue (12): 62-78.doi: 10.11959/j.issn.2096-109x.2017.00223

• Papers • Previous Articles    

Flow consistency in an intensive SDN security architecture with multiple controllers

Ying-ying LV,Yun-fei GUO,Chao QI,Qi WU,Ya-wen WANG   

  • Revised:2017-11-08 Online:2017-12-01 Published:2018-01-12
  • Supported by:
    The National Natural Science Foundation of China(61521003);The National Natural Science Foundation of China(61602509);The National Key R&D Program of China(2016YFB0800100);The National Key R&D Program of China(2016YFB0800101);The Key Technologies Research and Development of Program of Henan Province(172102210615)

Abstract:

As critical components in SDN,controllers are prone to suffer from a series of potential attacks which result in system crashes.To prevent the compromise caused by single failure of controller or flow-tampering attacks,Mcad-SA,an aware decision-making security architecture with multiple controllers was proposed,which coordinates heterogeneous controllers internally as an“associated”controller.This architecture extends existing control plane and takes advantage of various controllers’merits to improve the difficulty and cost of probes and attacks from attackers.In this framework,flow rules distributed to switches are no longer relying on a single controller but according to the vote results from the majority of controllers,which significantly enhances the reliability of flow rules.As to the vote process of flow rules,segmentation and grading is adopted to pick up the most trustful one from multiple flow rules and implement flow consistency.This mechanism avoids comparison between rules via bit by bit which is impractical among several controllers.Theory analysis and simulation results demonstrates the effectiveness,availability and resilience of the proposed methods and their better security gain over general SDN architectures.

Key words: multi-controller, security, Mcad-SA, flow consistency

No Suggested Reading articles found!