Skip to main navigation Skip to search Skip to main content

Enabling dynamic access control for controller applications in software-defined networks

  • Hitesh Padekar
  • , Younghee Park
  • , Hongxin Hu
  • , Sang Yoon Chang
  • San Jose State University
  • Advanced Digital Sciences Center

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

24 Scopus citations

Abstract

Recent findings have shown that network and system attacks in Software-Defined Networks (SDNs) have been caused by malicious network applications that misuse APIs in an SDN controller. Such attacks can both crash the controller and change the internal data structure in the controller, causing serious damage to the infrastructure of SDN-based networks. To address this critical security issue, we introduce a security framework called AEGIS to prevent controller APIs from being misused by malicious network applications. Through the run-Time verification of API calls, AEGIS performs a finegrained access control for important controller APIs that can be misused by malicious applications. The usage of API calls is verified in real time by sophisticated security access rules that are defined based on the relationships between applications and data in the SDN controller. We also present a prototypical implementation of AEGIS and demonstrate its effectiveness and efficiency by performing six different controller attacks including new attacks we have recently discovered.

Original languageEnglish
Title of host publicationSACMAT 2016 - Proceedings of the 21st ACM Symposium on Access Control Models and Technologies
PublisherAssociation for Computing Machinery
Pages51-61
Number of pages11
ISBN (Electronic)9781450338028
DOIs
StatePublished - Jun 6 2016
Event21st ACM Symposium on Access Control Models and Technologies, SACMAT 2016 - Shanghai, China
Duration: Jun 6 2016Jun 8 2016

Publication series

NameProceedings of ACM Symposium on Access Control Models and Technologies, SACMAT
Volume06-08-June-2016

Conference

Conference21st ACM Symposium on Access Control Models and Technologies, SACMAT 2016
Country/TerritoryChina
CityShanghai
Period06/6/1606/8/16

Keywords

  • Access control
  • API misuse
  • Network attacks
  • Security
  • Software-defined networks

Fingerprint

Dive into the research topics of 'Enabling dynamic access control for controller applications in software-defined networks'. Together they form a unique fingerprint.

Cite this