Protecting OpenFlow using Intel SGX

Jorge Medina, Nicolae Paladi, Patrik Arlos

Forskningsoutput: Kapitel i bok/rapport/Conference proceedingKonferenspaper i proceedingPeer review

158 Nedladdningar (Pure)

Sammanfattning

OpenFlow flow tables in Open vSwitch contain valuable information about installed flows, priorities, packet actions and routing policies. Their importance is emphasised when collocated tenants compete for the limited entries available to install flow rules. OpenFlow flow tables are a security asset that requires confidentiality and integrity guarantees. However, commodity software switch implementations - such as Open vSwitch - do not implement protection mechanisms capable to prevent attackers from obtaining information about the installed flows or modifying flow tables. We adopt a novel approach to enabling OpenFlow flow table protection through decomposition. We identify core assets requiring security guarantees, isolate OpenFlow flow tables through decomposition and implement a prototype using Open vSwitch and Software Guard Extensions enclaves. An evaluation of the prototype on a distributed testbed both demonstrates that the approach is practical and indicates directions for further improvements.
Originalspråkengelska
Titel på värdpublikationIEEE Conference on Network Function Virtualization and Software Defined Networks
Undertitel på värdpublikation(NFV-SDN)
FörlagIEEE - Institute of Electrical and Electronics Engineers Inc.
ISBN (elektroniskt)978-1-7281-4545-7
ISBN (tryckt)978-1-7281-4546-4
DOI
StatusPublished - 2020 mars 19
EvenemangIEEE Conference on Network Function Virtualization and Software Defined Networks - Dallas, USA
Varaktighet: 2019 nov. 122019 nov. 14

Konferens

KonferensIEEE Conference on Network Function Virtualization and Software Defined Networks
Land/TerritoriumUSA
OrtDallas
Period2019/11/122019/11/14

Ämnesklassifikation (UKÄ)

  • Datorsystem

Fingeravtryck

Utforska forskningsämnen för ”Protecting OpenFlow using Intel SGX”. Tillsammans bildar de ett unikt fingeravtryck.

Citera det här