Securing software-defined WAN through analyzing network attack surfaces네트워크 공격 표면 분석을 통한 소프트웨어 정의 WAN 보안성 향상에 관한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 123
  • Download : 0
Today's Software-Defined Networking (SDN) is expanding its deployment area to wide area networks (WAN) to improve bandwidth utilization or optimize routing paths in large-scale networking environments. This paradigm, also known as Software-Defined WAN (SD-WAN), is a widely accepted concept in a variety of networking companies such as Google, Microsoft, and AT\&T. However, despite of its significant benefits, we posit that the security aspect of SD-WAN has been understudied so far. This dissertation aims to explore the security issues of SD-WAN by analyzing network attack surfaces from the two SD-WAN layers: (i) data-layer and (ii) control-layer. In the data-layer, we focus on the architectural bottlenecks in WANs, such as core switches and links whose failure causes significant disruption to entire networks. Then, we propose two network topology obfuscation systems, BottleNet and EqualNet so that adversaries cannot discover such bottlenecks from a network topology. In the control-layer, we posit that adversaries can abuse the East-West interfaces used for communication between distributed controllers. To this end, we propose to design an attack injection system for distributed controllers, Ambusher that systematically finds attack scenarios from distributed SDN controllers by learning internal states of a cluster. Even though our research is insufficient to address all security problems in SD-WAN, we believe that this dissertation takes an important step toward enhancing the security of SD-WAN.
Advisors
Shin, Seungwonresearcher신승원researcher
Description
한국과학기술원 :전기및전자공학부,
Publisher
한국과학기술원
Issue Date
2022
Identifier
325007
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 전기및전자공학부, 2022.2,[vii, 94 p. :]

Keywords

Software-defined networking (SDN)▼aSoftware-defined WAN (SD-WAN)▼aDDoS attacks▼aDistributed systems▼aNetwork security; 소프트웨어 정의 네트워킹▼a소프트웨어 정의 WAN▼aDDoS 공격▼a분산 시스템▼a네트워크 보안

URI
http://hdl.handle.net/10203/309133
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=1006556&flag=dissertation
Appears in Collection
EE-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0