– Connectivity loss between forwarding devices and
controller(s)
e-mail: (see
J. Rak is with the Telecommunications and Informatics Department of
– State consistency between the controller replicas
• Threats affecting the controller
and encryption of the secure channel is crucial. Unfortunately
authentication is not always supported in the current SDN
improving sdn survivability,” in 2014 IEEE Global Communications
ecosystem [22].
[10] P. Vizarreta, C. M. Machuca, and W. Kellerer, “Controller placement
strategies for a resilient sdn control plane,” in Resilient Networks Design
C. Attacks from the Application Plane
2016, pp. 253–259.
Additional risks can turn up from the usage of malicious
or malfunctioning SDN applications. This can be relieved
using formal verification methods in the controller [23]. These
[12] Linux Foundation, “Opendaylight.” [Online]. Available:
methods can be used to enforce security rules, like for example
the isolation of different network zones.
One issue for a secure operation of an SDN that remains
of the 2007 Conference on Applications, Technologies, Architectures,
open is the verification of the security of all components and a
full bottom up trust relationship between all components and
[14] P. Kazemian, M. Chan, H. Zeng, G. Varghese, N. McKeown, and
S. Whyte, “Real time network policy checking using header space
V. CONCLUSION
[15] S. Shin and G. Gu, “Attacking software-defined networks: A first feasi-
This paper has given an overview of the most important
on Hot topics in software defined networking. ACM, 2013, pp. 165–
issues and some proposed solutions in order to increase the
reliability and security in Software Defined Networking. As
it has been mentioned, the flexibility and efficiency offered
Management (CNSM), 2014 10th International Conference on. IEEE,
by SDN comes with some challenges (e.g., higher software failures).
failures). [17] R. Klöti, V. Kotronis, and P. Smith, “OpenFlow: A security analysis,”
Proceedings - International Conference on Network Protocols, ICNP,
ACKNOWLEDGMENT
against SDN controllers,” 2015 International Conference on Computing,
This article is based upon work from COST Action CA
15127 (Resilient communication services protecting end-user
applications from disaster-based failures RECODIS) sup-
defined networks,” in IEEE Conference on Network Softwarization -
ported by COST (European Cooperation in Science and Technology.
nology. [20] K. Benton, L. J. Camp, and C. Small, “OpenFlow Vulnerability Assess-
ment Categories and Subject Descriptors,” Proceedings of the second
ACM SIGCOMM workshop on Hot topics in software defined networking
