SECURING THE SDN NORTHBOUND INTERFACE WITH THE AID OF ANOMALY DETECTION
Jan J. Laan · 2015
Software defined networking is an active research topic. Most research focuses on functionality, and security of the SDN infrastructure has only recently gained attention. However, research is mainly focused on the southbound interface. The SDN northbound interface, required for SDN applications to communicate with the controller has received few security attention. This research identifies the most important security features needed for a northbound interface to be secure. We tested several popular open-source SDN controllers for their support of these features. It shows that the overall status of these controllers is poor with regards to the security of their northbound interfaces. While some popular controllers support most important security features, they are almost all disabled by default, requiring some additional configuration. Other controllers offer few or no security features. An important feature missing for all controllers is authorization, the ability to restrict to which parts of the northbound interface an application has access. Also important is the case of the hacked application, which, by using the northbound interface, can disrupt the network without being detected or stopped. We propose a solution for detecting this, by using statistical anomaly detection. We have demonstrated some advantages of this solution, by using a prototype implementation. However, this solution requires more testing and validation to be fully usable.