Home / Current Issue / Paper 1706608
Securing Topology Discovery in Software Defined Networks: Trends, Gaps, and Future Directions
Subject area: Science,Engineering and Technology · Area of research: Computer Science
Abstract
Software Defined Networking (SDN) has revolutionized network architecture by separating the control plane from the data plane, offering enhanced flexibility, programmability, and centralized control. However, this paradigm shift introduces significant security concerns, particularly in the area of topology discovery, where threats such as topology poisoning, link fabrication, and host hijacking are prevalent due to the lack of standardization in SDN protocols and the dynamic nature network environments like virtual data centers and cloud infrastructures. This survey explores various security mechanisms proposed for topology discovery in SDN, with a focus on the OpenFlow protocol. It reviews key approaches designed to mitigate common vulnerabilities, including the use of authentication, encryption, and anomaly detection techniques. The survey highlights the trade-offs between security measures and network performance, analyzing their effectiveness in addressing topology-related threats while minimizing overhead. The findings suggest that while many solutions enhance SDN security, challenges such as resource consumption, latency, and packet processing overhead persist. Future research should aim to develop lightweight, scalable mechanisms that balance robust security with operational efficiency, ensuring optimal performance of SDN in dynamic, large-scale networks.
Keywords
Software Defined Network, Topology Discovery, Link Layer Discovery Protocol (LLDP), OpenFlow
References
[1] Alharbi T., Portmann M., and Pakzad F. (2015, October). The (in)security of topology discovery in software defined networks. In 40th IEEE Conference on Local Computer Networks, LCN 2015, Clearwater Beach, FL, USA, pages 502–505.
[2] Dhawan M., Poddar R., Mahajan K., and Mann V. (2015, January). SPHINX: Detecting Security Attacks in Software-Defined Networks. DOI: 10.14722/ndss.2015.23064
[3] Duan, Q., N. Ansari, and M. Toy (2016, October). Software-Defined Network Virtualization: An architectural framework for integrating SDN and NFV for service provisioning in future networks. IEEE Network.
[4] Hong S., Xu L., Wang H. and Gu G. (2015, February). Poisoning Network Visibility in Software-Defined Networks: New Attacks and Countermeasures, in: Proc. of Annual Network and Distributed System Security Symposium (NDSS'15).
[5] Huang, X., P. Shi, Y. Liu, and F. Xu (2020, April). TrustTopo, a lightweight and efficient SDN topology verification scheme. East China Normal University, Shanghai, China. Computer Networks 170 (2020), 107119.
[6] Jain, S., A. Kumar, S. Mandal, and J. Ong et al. (2013, August). B4: Experience with a globally-deployed Software Defined WAN. In ACM SIGCOMM Conference. Pages 3–14.
[7] Jammal, M., T. Singh, A. Shami, and R. Asal et al. (2014, July). Software defined networking: State of the art and research challenges. Computer Networks 72 (0), 74–98. DOI: 10.1016/j.comnet.2014.07.004.
[8] Jimenez, Y., C. Cervello-Pastor, and A. Garcia (May, 2015). Dynamic resource discovery protocol for software defined networks. IEEE Commun. Lett. 19(5), 743–746.
[9] Kloti, R., V. Kotronis, and P. Smith (2013, October). OpenFlow: A security analysis. In IEEE International Conference on Network Protocols (ICNP). Pages 1–6.
[10] McKeown, N., T. Anderson, H. Balakrishnan, and G. Parulkar et al. (2008, March). OpenFlow: enabling innovation in campus networks. ACM SIGCOMM Computer Communication Review, pages 69–74.
[11] Nehra, M., M. Tripathi, S. Gaur, and R. B. Battula et al. (2018, December). SLDP: A secure and lightweight link discovery protocol for software-defined networking.
[12] Ochoa-Aday, L., C. Cervelló-Pastor, and A. Fernández-Fernándeza (2016, November). Discovering the Network Topology: An efficient approach for software-defined networks. Advances in Distributed Computing and Artificial Intelligence Journal. ADCAIJ, Regular Issue Vol. 5 N. 2. http://adcaij.usal.es.
[13] Ochoa-Aday, L., C. Cervello-Pastor, and A. Fernandez-Fernandez (March, 2018). Self-healing topology discovery protocol for software-defined networks. IEEE Commun. Lett. 22(5), 1070–1073.
[14] Pakzad, F., M. Portmann, W. Tan, and J. Indulska (2015, September). Efficient topology discovery in OpenFlow-based software defined networks. Computer Communications, DOI: 10.1016/j.comcom.2015.09.013.
[15] Tarnaras, G., E. Haleplidis, and S. Denazis (April, 2015). SDN and FORCES-based optimal network topology discovery. Proceedings of the 2015 1st IEEE Conference on Network Softwarization (NetSoft), 1–6.
[16] Wang, H., G. Yang, P. Chinprutthiwong, and L. Xu et al. (2018, October). Towards fine-grained network security forensics and diagnosis in the SDN era. In ACM SIGSAC Conference on Computer and Communications Security (CCS), pages 3–16.
[17] Xu, L., J. Huang, S. Hong, and J. Zhang et al. (2018, August). Attacking the brain: Races in the SDN control plane. In USENIX Security Symposium, pages 451–468.
[18] Xue, L., X. Ma, X. Luo, and E. W.W. Chan et al. (2018, October). LinkScope: Towards detecting target link flooding attacks. IEEE Transactions on Information Forensics and Security (TIFS).
[19] Zhang, M., G. Li, L. Xu, and J. Bi et al. (2018, September). Control plane reflection attacks in SDNs: New attacks and countermeasures. In Symposium on Research in Attacks, Intrusions, and Defenses (RAID).
[20] Zuo, Z., R. He, X. Zhu, and C. Chang (2019, May). A novel software-defined network packet security tunnel forwarding mechanism. Mathematical Biosciences and Engineering (MBE), 16(5), 4359–4381. DOI: 10.3934/mbe.2019217.
[21] (2021, March 30). Retrieved from OpenDaylight: URL http://www.opendaylight.org/project/technical-overview.
How to cite this paper
@article{1706608,
author = {Ahmad Enesi Siyaka, Salisu Aliyu, Sahabi Yusuf Ali},
title = {Securing Topology Discovery in Software Defined Networks: Trends, Gaps, and Future Directions},
journal = {Iconic Research And Engineering Journals},
year = {2024},
volume = {8},
number = {5},
pages = {584-592},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1706608.pdf},
abstract = {Software Defined Networking (SDN) has revolutionized network architecture by separating the control plane from the data plane, offering enhanced flexibility, programmability, and centralized control. However, this paradigm shift introduces significant security concerns, particularly in the area of topology discovery, where threats such as topology poisoning, link fabrication, and host hijacking are prevalent due to the lack of standardization in SDN protocols and the dynamic nature network environments like virtual data centers and cloud infrastructures. This survey explores various security mechanisms proposed for topology discovery in SDN, with a focus on the OpenFlow protocol. It reviews key approaches designed to mitigate common vulnerabilities, including the use of authentication, encryption, and anomaly detection techniques. The survey highlights the trade-offs between security measures and network performance, analyzing their effectiveness in addressing topology-related threats while minimizing overhead. The findings suggest that while many solutions enhance SDN security, challenges such as resource consumption, latency, and packet processing overhead persist. Future research should aim to develop lightweight, scalable mechanisms that balance robust security with operational efficiency, ensuring optimal performance of SDN in dynamic, large-scale networks.},
keywords = {Software Defined Network, Topology Discovery, Link Layer Discovery Protocol (LLDP), OpenFlow },
month = {November},
}