The importance of cloud computing has grown over the last years, which resulted in a significant increase of Data Center (DC) network requirements. Virtualisation is one of the key drivers of that transformation and enables a massive deployment of computing resources, which exhausts server capacity limits. Furthermore, the increased network endpoints need to be handled dynamically and centrally to facilitate cloud computing functionalities. Traditional DCs barely satisfy those demands because of their inherent limitations based on the network topology. Software-Defined Networks (SDN) promise to meet the increasing network requirements for cloud applications by decoupling control functionalities from data forwarding. Although SDN solutions add more flexibility to DC networks, they also pose new vulnerabilities with a high impact due to the centralised architecture. In this paper we propose an evaluation framework for assessing the security level of SDN architectures in four different stages. Furthermore, we show in an experimental study, how the framework can be used for mapping SDN threats with associated vulnerabilities and necessary mitigations in conjunction with risk and impact classification. The proposed framework helps administrators to evaluate the network security level, to apply countermeasures for identified SDN threats, and to meet the networks security requirements.
翻译:云计算的重要性在过去几年中不断增长,这导致数据中心(DC)网络需求显著增加。虚拟化是该转型的关键驱动力之一,它使得计算资源的大规模部署成为可能,但同时也限制了服务器容量。此外,由于网络端点数量的增加,需要一种动态的中心化处理方式以支持云计算功能。传统的数据中心由于其网络拓扑结构的天然限制,难以满足这些需求。软件定义网络(SDN)通过将控制功能与数据转发解耦,为云应用满足日益增长的网络需求提供了更多的灵活性。虽然SDN解决方案给DC网络增加了更多的灵活性,但由于其集中化架构,也带来了新的漏洞,并产生了高影响。本文提出了一个评估框架,用于评估SDN架构的安全级别,包括四个不同的阶段。此外,我们在一项实验研究中展示了该框架如何与风险和影响分类相结合,用于映射带有关联漏洞、必要减轻措施的SDN威胁。所提出的框架帮助管理员评估网络安全级别,针对发现的SDN威胁应用对策,满足网络的安全要求。