SlideShare a Scribd company logo
SDNandSecurity
August 2013
Cristiano Monteiro, Solutions Architect at HP
cmonteiro@hp.com
@crmonteir
What isSDN?
3
Evolution of Server Architectures
Proprietary Hardware
Proprietary
Operating Systems
Proprietary
Applications
Innovation!
Standard Intel x86-based systems
Standard Operating Systems
(Linux, Windows, etc)
App
…
Standard interfaces and programming languages
Standard interfaces
App App
4
Evolution of Network Architectures
Proprietary Hardware
Proprietary OS
OS-Integrated Features
Standard “programmable” systems
RoutingMCast
…QoS
Standard interfaces and control protocols
Open interfaces and programming languages
Network features (applications)
Centralized Control Plane
Innovation!
5
… In the SDN architecture, the control and data planes are
decoupled, network intelligence and state are logically
centralized and the underlying network infrastructure is
abstracted from the applications …
Open Networking Foundation on SDN
Source: opennetworking.org
SDN Architecture
7
We need a new way to talk with Network
APP
Network Infrastructure Layer
How the apps requirements are
tied to Network Level ?
• Bandwidth Resources
• Isolation
• Security etc.
Understood !!!
Security Infrastructure Layer
App Guy talks to Net and
Security Teams
8
Ability to Apply Business Logic to Network Behavior in Dynamic Fashion
HP Delivers SDN to Achieve Agility
Infrastructure
Layer
SDNArchitecture
Control
Layer
Application
Layer
Separate control and data plane; abstract control
plane of many devices to one
Open standard-based programmatic access to
infrastructure
Deliver open programmable interfaces to
automate orchestration of network services
9
Separate control and data plane; abstract control
plane of many devices to one
Deliver open programmable interfaces to
automate orchestration of network services
Open standard-based programmatic access to
infrastructure
Deliver open programmable interfaces to
automate orchestration of network services
Ability to Apply Business Logic to Network Behavior in Dynamic Fashion
HP Delivers SDN to Achieve Agility
Separate control and data plane; abstract control
plane of many devices to one
Deliver open programmable interfaces to
automate orchestration of network services
Open standard-based programmatic access to
infrastructure Network Device Network DeviceNetwork Device
Control & Data Plane Programmable
Interface (e.g., OpenFlow)
Network ApplicationsNetwork ApplicationsSDN Applications
Business ApplicationsBusiness ApplicationsBusiness Applications
(e.g., OpenStack, CloudStack)
Cloud Orchestration
SDN Controller
Programmable Open APIs (e.g., REST)
Infrastructure
Layer
SDNArchitecture
Control
Layer
Application
Layer
10
Openflow (e.g. SouthBound Interface)
Both fine and coarse grain flow control possible.
10
switch
controller
actionsmatch rules
Forward to IDS Tunnel Port
Rate Limit, Forward Normal
Forward Normal
TCP Port 16384
TCP Port 80 from 01:23:45:67:89:ab
* (wildcard)
11
Openstack Quantum a.k.a Neutron (E.g. Northbound
Interface)
12
A B
2
3
4
5 61
ICMP
HTTP
Controller
TE - APP
HTTP - path 1
ICMP - path 2
Match srcpip=A,dstip=B prot=TCP dstport 80
Action In=port 1, Out=port 3
1
2
3
Match srcpip=A,dstip=B prot=ICMP
ActionIn=port 1, Out=port 2
Applicatin Example : SDN Traffic Engineering
SDN–SecurityUserCases
14
Detection : Anomaly Traffic, Signatures, Customer rings...
Reaction and mitigation : Filters, Destination Filters to null
“The right dose differentiates a poison and a remedy”
Objective : Even under attack the customer should be online.
Solutions to do that are very expensive....
Ddos Mitigation
15
Ddos Mitigation - Case 1
• Sakura Internet case.
(http://www.sakura.ne.jp/)
• Ddos Mitigation
• Voltdb for accurate detection src-dst
• dRTBH with openflow
16
Ddos Mitigation – Case 2
• Sflow-RT application to detect
• Openflow to mitigate.
17
SDN - NAC /MSM Concept
NAC Today:
Agent 802.1x
Suplicant 802.1x
Authenticator 802.1x
Almost impossible multivendor solution.
Conceptual
SDN NAC App.
Switches, AP´s
should support SBI (Eg. Openflow)
Radius
SDN Nac App
quarantine
18
Repudiation Services
Core
Distribution
Edge
Repudiation
IPS/ IDS
with SDN Application
• Reputation(pingserver.info) Malware
• Alert administrator
19
SDN Impact on Security Architecture
Scale up... The limit will be reached someday
and Single Point of Failure....
Redundancy but What about Flow table ?
Scale Out. An external device
Who will balance the load balancer ?
20
SDN Impact on Security Architecture
• Network will execute basic filtering.
• Controller combined with a SEC APP can
centralize flow table.
• NBI interface will allow new applications
came out.
• Complex tasks (e.g. DPI) can be performed
by a separated “Service Plane” .
• Cloud Security can use SDN to scale out.
21
SDN and Security a lot of opportunities...
core
Access
cloud
DC
Enterprise
Branches
Internet
DC
Security
22
What happens if a bad guy take the control of controller ?
A. Well you are in trouble but what happened if the same bad guy take the
control of a Border router in Service Provider environment today ???
What happens if a bad guy try to D.o.S the controller ?
A. Well the bad guy should have access to management network. .. You already
in trouble before the D.o.S
There are a lot of drawbacks likewise if you look for problems in the traditional
architectures you also find a lot...
SDN Drawbacks
23
Summary
SDN unlocks constrained
networks, accelerates innovation
and drives value out of networks
-
SDN Provides Abstraction of Complexity
- Lower cost of administration
- Reduce automation risk & difficulty
Network Simplification Drives Adoption
-
SDN Enhances & Enables Network Services
- Extend life and improve performance of
‘middle boxes’
- Reduce TCO of basic services
- Improve business QoE through integration of
apps & networks
Network Innovation Drives Advantage
Q&A
Thankyou

More Related Content

PPTX
The Potential Impact of Software Defined Networking SDN on Security
Brent Salisbury
 
PDF
SDN Security Talk - (ISC)2_3
Wen-Pai Lu
 
PDF
Security Advantages of Software-Defined Networking
Priyanka Aash
 
PPTX
Sdn pres v2-Software-defined networks
ahmad abdelhafeez
 
PDF
SDN Security: Two Sides of the Same Coin
Zivaro Inc
 
DOCX
SDN-Security
Paras Hematbhai Dudhatra
 
PPTX
Radware DefenseFlow-The SDN Application That Programs Networks for DoS Security
Radware
 
PPT
Security of software defined networking (sdn) and cognitive radio network (crn)
Ameer Sameer
 
The Potential Impact of Software Defined Networking SDN on Security
Brent Salisbury
 
SDN Security Talk - (ISC)2_3
Wen-Pai Lu
 
Security Advantages of Software-Defined Networking
Priyanka Aash
 
Sdn pres v2-Software-defined networks
ahmad abdelhafeez
 
SDN Security: Two Sides of the Same Coin
Zivaro Inc
 
Radware DefenseFlow-The SDN Application That Programs Networks for DoS Security
Radware
 
Security of software defined networking (sdn) and cognitive radio network (crn)
Ameer Sameer
 

What's hot (20)

PPTX
SDN - a new security paradigm?
Sophos Benelux
 
PDF
Attacking SDN infrastructure: Are we ready for the next gen networking
Priyanka Aash
 
PDF
SDN-ppt-new
Gifty Susan Mani
 
ODP
OWASP Brisbane - SDN Security
David Jorm
 
PPTX
SDN Analytics & Security
Scott Raynovich
 
PPTX
SDN: is it a solution for network security?
ARCCN
 
PDF
44CON & Ruxcon: SDN security
David Jorm
 
PPTX
Software defined networking players
Ameer Sameer
 
PPTX
Software Defined Network (SDN)
Ahmed Ayman
 
PDF
Evaluation of Authentication Mechanisms in Control Plane Applications for Sof...
Siyabonga Masuku
 
PDF
The New Landscape of Airborne Cyberattacks
Priyanka Aash
 
PDF
IntelFlow: Toward adding Cyber Threat Intelligence to Software Defined Networ...
Open Networking Perú (Opennetsoft)
 
PDF
Solving the Visibility Gap for Effective Security
Lancope, Inc.
 
PDF
IRJET- SDN Simulation in Mininet to Provide Security Via Firewall
IRJET Journal
 
PDF
How Automated Vulnerability Analysis Discovered Hundreds of Android 0-days
Priyanka Aash
 
PDF
Parrot Drones Hijacking
Priyanka Aash
 
PPTX
ioT_SDN
Raluca Ciungu
 
PDF
DDoS Attack Detection & Mitigation in SDN
Chao Chen
 
PDF
Windows Service Hardening
Digital Bond
 
PPTX
What's New in StealthWatch v6.5
Lancope, Inc.
 
SDN - a new security paradigm?
Sophos Benelux
 
Attacking SDN infrastructure: Are we ready for the next gen networking
Priyanka Aash
 
SDN-ppt-new
Gifty Susan Mani
 
OWASP Brisbane - SDN Security
David Jorm
 
SDN Analytics & Security
Scott Raynovich
 
SDN: is it a solution for network security?
ARCCN
 
44CON & Ruxcon: SDN security
David Jorm
 
Software defined networking players
Ameer Sameer
 
Software Defined Network (SDN)
Ahmed Ayman
 
Evaluation of Authentication Mechanisms in Control Plane Applications for Sof...
Siyabonga Masuku
 
The New Landscape of Airborne Cyberattacks
Priyanka Aash
 
IntelFlow: Toward adding Cyber Threat Intelligence to Software Defined Networ...
Open Networking Perú (Opennetsoft)
 
Solving the Visibility Gap for Effective Security
Lancope, Inc.
 
IRJET- SDN Simulation in Mininet to Provide Security Via Firewall
IRJET Journal
 
How Automated Vulnerability Analysis Discovered Hundreds of Android 0-days
Priyanka Aash
 
Parrot Drones Hijacking
Priyanka Aash
 
ioT_SDN
Raluca Ciungu
 
DDoS Attack Detection & Mitigation in SDN
Chao Chen
 
Windows Service Hardening
Digital Bond
 
What's New in StealthWatch v6.5
Lancope, Inc.
 
Ad

Similar to Sdn&security (20)

PPTX
Software Defined networking (SDN)
Milson Munakami
 
PPTX
Introduction to Software Defined Networking (SDN)
Bangladesh Network Operators Group
 
PDF
Introduction to Software Defined Networking (SDN) presentation by Warren Finc...
APNIC
 
PPTX
The Juniper SDN Landscape
Chris Jones
 
PPTX
Demystifying Software Defined Networking (SDN)
Matt Bynum
 
PPTX
Demystifying Software Defined Networking (SDN)
Matt Bynum
 
PPTX
Cis sem sdn
Lino Quivén
 
PDF
08 sdn system intelligence short public beijing sdn conference - 130828
Mason Mei
 
PPTX
Software Defined Networks
Shreeya Shah
 
PDF
WWT Software-Defined Networking Guide
Joel W. King
 
PPTX
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...
Christian Esteve Rothenberg
 
PDF
SDN and Security: A Marriage Made in Heaven. Or Not.
Priyanka Aash
 
PPTX
Lqsqsssssssssssssssssssssssssssssssssssq18.pptx
pfeprojet
 
PDF
Provide a diagram and description of the flow table entries that can.pdf
arihantelehyb
 
PPTX
lect1_intro_SDN introductionpptnew1.pptx
anchitaa1
 
PPTX
SDN 101: Software Defined Networking Course - Sameh Zaghloul/IBM - 2014
SAMeh Zaghloul
 
PDF
sdnppt.pdf
AbhayDonde
 
PDF
PLNOG 17 - Andrzej Jeruzal - Dell Networking OS10: sieciowy system operacyjny...
PROIDEA
 
PPTX
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
Aruba, a Hewlett Packard Enterprise company
 
PPTX
btNOG 9 presentation Introduction to Software Defined Networking
APNIC
 
Software Defined networking (SDN)
Milson Munakami
 
Introduction to Software Defined Networking (SDN)
Bangladesh Network Operators Group
 
Introduction to Software Defined Networking (SDN) presentation by Warren Finc...
APNIC
 
The Juniper SDN Landscape
Chris Jones
 
Demystifying Software Defined Networking (SDN)
Matt Bynum
 
Demystifying Software Defined Networking (SDN)
Matt Bynum
 
Cis sem sdn
Lino Quivén
 
08 sdn system intelligence short public beijing sdn conference - 130828
Mason Mei
 
Software Defined Networks
Shreeya Shah
 
WWT Software-Defined Networking Guide
Joel W. King
 
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...
Christian Esteve Rothenberg
 
SDN and Security: A Marriage Made in Heaven. Or Not.
Priyanka Aash
 
Lqsqsssssssssssssssssssssssssssssssssssq18.pptx
pfeprojet
 
Provide a diagram and description of the flow table entries that can.pdf
arihantelehyb
 
lect1_intro_SDN introductionpptnew1.pptx
anchitaa1
 
SDN 101: Software Defined Networking Course - Sameh Zaghloul/IBM - 2014
SAMeh Zaghloul
 
sdnppt.pdf
AbhayDonde
 
PLNOG 17 - Andrzej Jeruzal - Dell Networking OS10: sieciowy system operacyjny...
PROIDEA
 
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
Aruba, a Hewlett Packard Enterprise company
 
btNOG 9 presentation Introduction to Software Defined Networking
APNIC
 
Ad

Recently uploaded (20)

PPTX
Simple and concise overview about Quantum computing..pptx
mughal641
 
PDF
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
PDF
AI-Cloud-Business-Management-Platforms-The-Key-to-Efficiency-Growth.pdf
Artjoker Software Development Company
 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 
PPTX
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
PDF
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
PDF
Software Development Methodologies in 2025
KodekX
 
PDF
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PDF
The Future of Artificial Intelligence (AI)
Mukul
 
PDF
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
PDF
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PDF
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
PDF
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
PPTX
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
Simple and concise overview about Quantum computing..pptx
mughal641
 
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
AI-Cloud-Business-Management-Platforms-The-Key-to-Efficiency-Growth.pdf
Artjoker Software Development Company
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
Software Development Methodologies in 2025
KodekX
 
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
The Future of Artificial Intelligence (AI)
Mukul
 
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 

Sdn&security

  • 3. 3 Evolution of Server Architectures Proprietary Hardware Proprietary Operating Systems Proprietary Applications Innovation! Standard Intel x86-based systems Standard Operating Systems (Linux, Windows, etc) App … Standard interfaces and programming languages Standard interfaces App App
  • 4. 4 Evolution of Network Architectures Proprietary Hardware Proprietary OS OS-Integrated Features Standard “programmable” systems RoutingMCast …QoS Standard interfaces and control protocols Open interfaces and programming languages Network features (applications) Centralized Control Plane Innovation!
  • 5. 5 … In the SDN architecture, the control and data planes are decoupled, network intelligence and state are logically centralized and the underlying network infrastructure is abstracted from the applications … Open Networking Foundation on SDN Source: opennetworking.org
  • 7. 7 We need a new way to talk with Network APP Network Infrastructure Layer How the apps requirements are tied to Network Level ? • Bandwidth Resources • Isolation • Security etc. Understood !!! Security Infrastructure Layer App Guy talks to Net and Security Teams
  • 8. 8 Ability to Apply Business Logic to Network Behavior in Dynamic Fashion HP Delivers SDN to Achieve Agility Infrastructure Layer SDNArchitecture Control Layer Application Layer Separate control and data plane; abstract control plane of many devices to one Open standard-based programmatic access to infrastructure Deliver open programmable interfaces to automate orchestration of network services
  • 9. 9 Separate control and data plane; abstract control plane of many devices to one Deliver open programmable interfaces to automate orchestration of network services Open standard-based programmatic access to infrastructure Deliver open programmable interfaces to automate orchestration of network services Ability to Apply Business Logic to Network Behavior in Dynamic Fashion HP Delivers SDN to Achieve Agility Separate control and data plane; abstract control plane of many devices to one Deliver open programmable interfaces to automate orchestration of network services Open standard-based programmatic access to infrastructure Network Device Network DeviceNetwork Device Control & Data Plane Programmable Interface (e.g., OpenFlow) Network ApplicationsNetwork ApplicationsSDN Applications Business ApplicationsBusiness ApplicationsBusiness Applications (e.g., OpenStack, CloudStack) Cloud Orchestration SDN Controller Programmable Open APIs (e.g., REST) Infrastructure Layer SDNArchitecture Control Layer Application Layer
  • 10. 10 Openflow (e.g. SouthBound Interface) Both fine and coarse grain flow control possible. 10 switch controller actionsmatch rules Forward to IDS Tunnel Port Rate Limit, Forward Normal Forward Normal TCP Port 16384 TCP Port 80 from 01:23:45:67:89:ab * (wildcard)
  • 11. 11 Openstack Quantum a.k.a Neutron (E.g. Northbound Interface)
  • 12. 12 A B 2 3 4 5 61 ICMP HTTP Controller TE - APP HTTP - path 1 ICMP - path 2 Match srcpip=A,dstip=B prot=TCP dstport 80 Action In=port 1, Out=port 3 1 2 3 Match srcpip=A,dstip=B prot=ICMP ActionIn=port 1, Out=port 2 Applicatin Example : SDN Traffic Engineering
  • 14. 14 Detection : Anomaly Traffic, Signatures, Customer rings... Reaction and mitigation : Filters, Destination Filters to null “The right dose differentiates a poison and a remedy” Objective : Even under attack the customer should be online. Solutions to do that are very expensive.... Ddos Mitigation
  • 15. 15 Ddos Mitigation - Case 1 • Sakura Internet case. (http://www.sakura.ne.jp/) • Ddos Mitigation • Voltdb for accurate detection src-dst • dRTBH with openflow
  • 16. 16 Ddos Mitigation – Case 2 • Sflow-RT application to detect • Openflow to mitigate.
  • 17. 17 SDN - NAC /MSM Concept NAC Today: Agent 802.1x Suplicant 802.1x Authenticator 802.1x Almost impossible multivendor solution. Conceptual SDN NAC App. Switches, AP´s should support SBI (Eg. Openflow) Radius SDN Nac App quarantine
  • 18. 18 Repudiation Services Core Distribution Edge Repudiation IPS/ IDS with SDN Application • Reputation(pingserver.info) Malware • Alert administrator
  • 19. 19 SDN Impact on Security Architecture Scale up... The limit will be reached someday and Single Point of Failure.... Redundancy but What about Flow table ? Scale Out. An external device Who will balance the load balancer ?
  • 20. 20 SDN Impact on Security Architecture • Network will execute basic filtering. • Controller combined with a SEC APP can centralize flow table. • NBI interface will allow new applications came out. • Complex tasks (e.g. DPI) can be performed by a separated “Service Plane” . • Cloud Security can use SDN to scale out.
  • 21. 21 SDN and Security a lot of opportunities... core Access cloud DC Enterprise Branches Internet DC Security
  • 22. 22 What happens if a bad guy take the control of controller ? A. Well you are in trouble but what happened if the same bad guy take the control of a Border router in Service Provider environment today ??? What happens if a bad guy try to D.o.S the controller ? A. Well the bad guy should have access to management network. .. You already in trouble before the D.o.S There are a lot of drawbacks likewise if you look for problems in the traditional architectures you also find a lot... SDN Drawbacks
  • 23. 23 Summary SDN unlocks constrained networks, accelerates innovation and drives value out of networks - SDN Provides Abstraction of Complexity - Lower cost of administration - Reduce automation risk & difficulty Network Simplification Drives Adoption - SDN Enhances & Enables Network Services - Extend life and improve performance of ‘middle boxes’ - Reduce TCO of basic services - Improve business QoE through integration of apps & networks Network Innovation Drives Advantage