Enabling Practical Software-defined Networking Security Applications with OFX
John Sonchack, Jonathan M. Smith, Adam J. Aviv, Eric Keller
摘要
Software Defined Networks (SDNs) are an appealing platform for network security applications. However, existing approaches to building security applications on SDNs are not practical because of performance and deployment challenges. Network security applications often need to analyze and process traffic in more advanced ways than SDN data plane implementations, such as OpenFlow, allow. Much of an application ends up running on the centralized controller, which forms an inherent bottleneck. Researchers have proposed application specific modifications to the underlying data plane to gain performance, but this results in a solution that is not deployable as it requires new switches and does not support all network security applications. In this paper, we introduce OFX (the OpenFlow Extension Framework) which harnesses the processing power of network switches to enable practical SDN security applications within an existing OpenFlow infrastructure. OFX allows applications to dynamically load software modules directly onto unmodified network switches where application-dependent processing/monitoring can execute closer to the data plane at a rate much closer to line speed. We implemented OFX modules for security applications including Silverline (ACSAC'13), BotMiner (Sec'08), and several others motivated by the custom OpenFlow extensions in Avant-Guard (CCS'13). We evaluated OFX on a Pica 8 3290 switch and found that processing traffic in an OFX module running on the switch had orders of magnitude less overhead than processing traffic at the controller. OFX increased the performance of the evaluated security application by 20-40x as compared to standard OpenFlow implementations and up to 1.25x when compared to middlebox implementations running on dedicated servers. This is all achieved without the need for additional or modified hardware. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- PSI: Precise Security Instrumentation for Enterprise NetworksTianlong Yu, Seyed Kaveh Fayaz, Michael P. Collins, Vyas Sekar 等NDSS 2017 · 被引用 64 次
- Mantis: Reactive Programmable SwitchesLiangcheng Yu, John Sonchack, Vincent LiuSIGCOMM 2020 · 被引用 37 次
- Programmable In-Network Security for Context-aware BYOD PoliciesQiao Kang, Lei Xue, Adam Morrison, Yuxin Tang 等USENIX Security 2020
相关 Paper
- SDN Application Backdoor: Disrupting the Service via Poisoning the TopologyShuhua Deng, Xian Qing, Xiaofan Li, Xing Gao 等INFOCOM 2023 · 被引用 8 次
- Safety Critical Networks using Commodity SDNsAshish Kashinath, Monowar Hasan, Rakesh Kumar, Sibin Mohan 等INFOCOM 2021 · 被引用 3 次
- Cross-App Poisoning in Software-Defined NetworkingBenjamin E. Ujcich, Samuel Jero, Anne Edmundson, Qi Wang 等CCS 2018 · 被引用 62 次
- Attacking the Brain: Races in the SDN Control PlaneLei Xu, Jeff Huang, Sungmin Hong, Jialong Zhang 等USENIX Security 2017 · 被引用 77 次
- The CrossPath Attack: Disrupting the SDN Control Channel via Shared LinksJiahao Cao, Qi Li, Renjie Xie, Kun Sun 等USENIX Security 2019 · 被引用 68 次
