sdn security: a survey - semantic scholar · presentation outline . 4 queen’s university belfast...

14
SDN Security: A Survey Dr. Sandra Scott-Hayward [email protected] SDN4FNS - November 2013

Upload: others

Post on 17-Aug-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

SDN Security: A Survey

Dr. Sandra Scott-Hayward

[email protected]

SDN4FNS - November 2013

Page 2: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

• Research at CSIT

• Security in SDN

• Security Analyses

• Security Enhancement using SDN

• Security Challenges with SDN

• Open Areas for Research

Presentation Outline

Page 3: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

4 Queen’s University Belfast Research Groups - Digital Communications - High Frequency Electronics - Speech, Imaging and Vision Systems - Secure Digital Systems

ECIT Institute (Est.2003)

Research Excellence & Innovation

180 people

Page 4: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

NETWORK SECURITY OPEN INNOVATION

TIERED MEMBERSHIP

KNOWLEDGE TRANSFER

VENTURE CREATION

CSIT (Est.2009)

DATA SECURITY

CYBER PHYSICAL SYSTEMS

MOBILE SECURITY

A GLOBAL

INNOVATION HUB FOR

CYBER SECURITY

Page 5: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

Est.2009, Based in The ECIT Institute

Initial funding over £30M

80 People

• Researchers

• Engineers

• Business Development

Largest UK University lab for cyber security

technology research

GCHQ Academic Centre of Excellence

Industry Informed

• Open Innovation Model

Strong international links

• ETRI, CyLab, GTRI, SRI International

• Cyber Security Technology Summit

Centre for Secure Information

Technologies (CSIT)

Page 6: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

Network Security Systems

Network Security

• IDS / IPS, DDoS mitigation

Cloud Security

• SDN, Virtualisation

SCADA & Smart Grid Security

• DDoS mitigation

Mobile Malware Analysis

• Reverse engineering

• Signature extraction

Prof. Sakir Sezer – Research Director

Page 7: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

SDN Architecture

Sezer, S., et al. “Are We Ready for SDN? Implementation Challenges for Software-Defined Networks” IEEE Communications Magazine, July 2013

Page 8: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

SDN Architecture

Page 9: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

SANE Architecture

SANE = Secure Architecture for the Networked Enterprise

2006 – M. Casado et al.

• Logically Centralized Server

• Trusted Domain

Controller (DC)

• Providing routing and

access control decisions

• Access Control Policies

• Authentication of Hosts and

Policy Enforcement

• Principle of least privilege and

least knowledge

Casado, M. et al. “SANE: A Protection Architecture for Enterprise Networks” USENIX Security Symposium, 2006

Page 10: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

Categorization of SDN Security

Issues

Page 11: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

Categorization of SDN Security

Research

Scott-Hayward, S., O’Callaghan, G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS, November 2013

Page 12: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

• Moving Target Defense

• Exploiting the dynamic and adaptive capabilities of SDN

• Trust (Application-Enabled SDN)

• Application-Control Interface and Control-Data

Interface

• Securing the Network Map

Open Research Areas

Page 14: SDN Security: A Survey - Semantic Scholar · Presentation Outline . 4 Queen’s University Belfast Research Groups ... G. and Sezer, S. “SDN Security: A Survey” IEEE SDN4FNS,

CSIT: A Global Cyber Innovation Hub

Thought leader in Secure Information Technology Research

Network of Commercial & Research partnerships

Portfolio of successful Technology Transfer