Skip to main navigation Skip to search Skip to main content

Securing SDN controller and switches from attacks

  • Udaya Tupakula
  • , Vijay Varadharajan
  • , Preeti Mishra

Research output: Contribution to journalArticlepeer-review

Abstract

In this paper, we propose techniques for securing the SDN controller and the switches from malicious end-host attacks. Our model makes use of trusted computing and introspection-based intrusion detection to deal with attacks in SDN. We have developed a security application for the SDN controller to validate the state of the switches in the data plane and enforce the security policies to monitor the virtual machines at system call level and detect attacks. We have developed a feature extraction method named vector of n-grams which represents the traces in an efficient way without losing the ordering of system calls. The flows from the malicious hosts are dropped before they are processed by the switches or forwarded to the SDN controller. Hence, our model protects the switches and the SDN controller from the attacks.

Original languageEnglish
Pages (from-to)77-91
JournalInternational Journal of High Performance Computing and Networking
Volume14
Issue number1
Publication statusPublished - 21 May 2019

Fingerprint

Dive into the research topics of 'Securing SDN controller and switches from attacks'. Together they form a unique fingerprint.

Cite this