A Simple Information Flow Security Model for Software-Defined Networks

Dmitry Ju. Chalyy, Evgeny S. Nikitin, Ekaterina Ju. Antoshina · DOAJ (DOAJ: Directory of Open Access Journals) · 2015

The software-defined networks (SDN) is an emerg- ing paradigm of the networking which became a enabler technol- ogy for many modern applications. Cloud computing is a promi- nent example in the list of such applications including policy- based access control, network virtualization and others. Software nature of the network management can provide flexibility and fast-paced innovations in the netwoking. The other side arise from a complex nature of software, thus, an increasing need for a means to assure its correctness and security. Despite of industrial introduction in cloud environements and other settings there is still a need for abstract models for SDN to tackle challenges in many directions: behavioural models, security models etc. [3]. The security is a broad field of study even if we limit our attention to software-defined networks security. Furthermore, we bring the confidentiality into our focus. This property asserts that the secret data can not be inferred by an attacker or unintentionally. This is a critical property for multi-tenant SDN environements since the network management software must ensure that no confidential data of one tenant are leaked to other tenants in spite of using the same physical infrastructure. We define a notion of end-to-end security in context of softare-defined networks and propose a model which makes possible to reason about confidentiality and to check that confidential information flows does not interfere with non-confidential ones.

Read the paper · More papers on PaperTik