Security Assessment in Software Defined Networks (SDN): Vulnerabilities, Challenges and Research Prospects
Amir Ali · Lahore Garrison University Research Journal of Computer Science and Information Technology · 2024
Conventional internet architecture facilitates users for different services and applications. Still, it faces numerous challenges like network management, QoS management for network virtualization, IP multicasting, deployment of IPV6, crucial security measures, end-to-end connectivity, interand inter-domain routing. To meet the demand for these services due to the rapid growth of technologies and traffic, an emerging network architecture termed Software Defined Network (SDN) with programmable technology has brought unprecedented management to control networks. Due to the separation of data, control, and application planes, the defined network provides cost-effective openness, centralized automation, programmable features as per user demands, and high resilience for network administrators. OpenFlow evolved as the first standard protocol for software-defined network control and data plane communication to meet changing business requirements. Although Software Defined Network brings enormous advancements in networks to support business applications, it is severely affected by cyber-attacks on data, control and application planes. Middle boxes play a significant role in managing network effectiveness and providing adequate security control fromexternal and internal security threats. However, they require proper management and configuration; otherwise, they can lead to devastating effects. This paper makes significant contributions by (1) Examining potential security attacks on various SDN layers and addressing inconsistent policies, (2) Identifying security concerns within SDN planes and proposing preventive measures against prevalent attacks, and (3) Delving into security threats, challenges, and research opportunities in SDN, with a focus on critical security controls like spam detectors, IDS/IPS, firewalls, and policy management. Researchers can use this article as a resource to comprehend the security landscape, including the current state of development and challenges explored by the scientific community in the realm of SDN.