Netinfo Security ›› 2015, Vol. 15 ›› Issue (2): 26-32.doi: 10.3969/j.issn.1671-1122.2015.02.005

Previous Articles     Next Articles

Analysis and Research on Network Security for OpenFlow-based SDN

ZUO Qing-yun(), ZHANG Hai-su   

  1. PLA Academy of National Defense Information, Wuhan Hubei 430010, China
  • Received:2014-11-13 Online:2015-02-10 Published:2015-07-05

Abstract:

OpenFlow-based SDN technology separates the data and control planes of network, deploys central controller to manage and control the network, and provides a new solution for the development of future network. However, this new method of network management and control differs essentially from traditional network management method using close network equipment with distributed control plane currently, which would introduce new management and security problems when achieving centralized management. In this paper, we firstly introduce the defects of the three-layer architecture itself and the possible security issues, and analyze these issues from infrastructure layer, southbound interface, control layer, northbound interface and application layer respectively. Then, we summarize current related research status and research methods, and provide feasible solutions from four aspects including authentication mechanisms, backup and recovery of control layer, network anomaly detection and defense mechanisms, application isolation and permission management. After the discussion, we conclude the paper and point out the research direction.

Key words: OpenFlow network, software defined networking, control layer, authentication, backup

CLC Number: