信息网络安全 ›› 2015, Vol. 15 ›› Issue (2): 26-32.doi: 10.3969/j.issn.1671-1122.2015.02.005

• 技术研究 • 上一篇    下一篇

基于OpenFlow的SDN网络安全分析与研究

左青云(), 张海粟   

  1. 国防信息学院,湖北武汉 430010
  • 收稿日期:2014-11-13 出版日期:2015-02-10 发布日期:2015-07-05
  • 作者简介:

    作者简介: 左青云(1986-),男,湖北,讲师,博士,主要研究方向:软件定义网络、信息资源管理;张海粟(1982-),男,安徽,讲师,博士,主要研究方向:数据挖掘。

  • 基金资助:
    国家自然科学基金[61379149]

Analysis and Research on Network Security for OpenFlow-based SDN

ZUO Qing-yun(), ZHANG Hai-su   

  1. PLA Academy of National Defense Information, Wuhan Hubei 430010, China
  • Received:2014-11-13 Online:2015-02-10 Published:2015-07-05

摘要:

基于OpenFlow的SDN技术将网络的数据平面和控制平面相分离,通过部署中央控制器来实现对网络的管控,为未来网络的发展提供了一种新的解决思路。然而,这种新型网络管控方法与传统网络在分布式控制平面上通过封闭网络设备进行管控的方法有着根本区别,因而在实现集中化管理的同时将引入新的管理和安全问题。文章首先介绍了其三层架构的自身缺陷和可能存在的安全问题,并从SDN架构的基础设施层、南向接口、控制层、北向接口和应用层等几个方面分别进行分析,总结出SDN不同层次存在安全问题的原因;随后,文章从认证机制、控制层的备份和恢复、网络异常识别和防御机制、应用隔离和权限管理等四个方面总结了当前的相关研究进展和研究思路,并提出了可行的解决方案;最后,对全文进行总结和展望。

关键词: OpenFlow网络, 软件定义网络, 控制层, 认证, 备份

Abstract:

OpenFlow-based SDN technology separates the data and control planes of network, deploys central controller to manage and control the network, and provides a new solution for the development of future network. However, this new method of network management and control differs essentially from traditional network management method using close network equipment with distributed control plane currently, which would introduce new management and security problems when achieving centralized management. In this paper, we firstly introduce the defects of the three-layer architecture itself and the possible security issues, and analyze these issues from infrastructure layer, southbound interface, control layer, northbound interface and application layer respectively. Then, we summarize current related research status and research methods, and provide feasible solutions from four aspects including authentication mechanisms, backup and recovery of control layer, network anomaly detection and defense mechanisms, application isolation and permission management. After the discussion, we conclude the paper and point out the research direction.

Key words: OpenFlow network, software defined networking, control layer, authentication, backup

中图分类号: