SlideShare a Scribd company logo
SDNandSecurity
August 2013
Cristiano Monteiro, Solutions Architect at HP
cmonteiro@hp.com
@crmonteir
What isSDN?
3
Evolution of Server Architectures
Proprietary Hardware
Proprietary
Operating Systems
Proprietary
Applications
Innovation!
Standard Intel x86-based systems
Standard Operating Systems
(Linux, Windows, etc)
App
…
Standard interfaces and programming languages
Standard interfaces
App App
4
Evolution of Network Architectures
Proprietary Hardware
Proprietary OS
OS-Integrated Features
Standard “programmable” systems
RoutingMCast
…QoS
Standard interfaces and control protocols
Open interfaces and programming languages
Network features (applications)
Centralized Control Plane
Innovation!
5
… In the SDN architecture, the control and data planes are
decoupled, network intelligence and state are logically
centralized and the underlying network infrastructure is
abstracted from the applications …
Open Networking Foundation on SDN
Source: opennetworking.org
SDN Architecture
7
We need a new way to talk with Network
APP
Network Infrastructure Layer
How the apps requirements are
tied to Network Level ?
• Bandwidth Resources
• Isolation
• Security etc.
Understood !!!
Security Infrastructure Layer
App Guy talks to Net and
Security Teams
8
Ability to Apply Business Logic to Network Behavior in Dynamic Fashion
HP Delivers SDN to Achieve Agility
Infrastructure
Layer
SDNArchitecture
Control
Layer
Application
Layer
Separate control and data plane; abstract control
plane of many devices to one
Open standard-based programmatic access to
infrastructure
Deliver open programmable interfaces to
automate orchestration of network services
9
Separate control and data plane; abstract control
plane of many devices to one
Deliver open programmable interfaces to
automate orchestration of network services
Open standard-based programmatic access to
infrastructure
Deliver open programmable interfaces to
automate orchestration of network services
Ability to Apply Business Logic to Network Behavior in Dynamic Fashion
HP Delivers SDN to Achieve Agility
Separate control and data plane; abstract control
plane of many devices to one
Deliver open programmable interfaces to
automate orchestration of network services
Open standard-based programmatic access to
infrastructure Network Device Network DeviceNetwork Device
Control & Data Plane Programmable
Interface (e.g., OpenFlow)
Network ApplicationsNetwork ApplicationsSDN Applications
Business ApplicationsBusiness ApplicationsBusiness Applications
(e.g., OpenStack, CloudStack)
Cloud Orchestration
SDN Controller
Programmable Open APIs (e.g., REST)
Infrastructure
Layer
SDNArchitecture
Control
Layer
Application
Layer
10
Openflow (e.g. SouthBound Interface)
Both fine and coarse grain flow control possible.
10
switch
controller
actionsmatch rules
Forward to IDS Tunnel Port
Rate Limit, Forward Normal
Forward Normal
TCP Port 16384
TCP Port 80 from 01:23:45:67:89:ab
* (wildcard)
11
Openstack Quantum a.k.a Neutron (E.g. Northbound
Interface)
12
A B
2
3
4
5 61
ICMP
HTTP
Controller
TE - APP
HTTP - path 1
ICMP - path 2
Match srcpip=A,dstip=B prot=TCP dstport 80
Action In=port 1, Out=port 3
1
2
3
Match srcpip=A,dstip=B prot=ICMP
ActionIn=port 1, Out=port 2
Applicatin Example : SDN Traffic Engineering
SDN–SecurityUserCases
14
Detection : Anomaly Traffic, Signatures, Customer rings...
Reaction and mitigation : Filters, Destination Filters to null
“The right dose differentiates a poison and a remedy”
Objective : Even under attack the customer should be online.
Solutions to do that are very expensive....
Ddos Mitigation
15
Ddos Mitigation - Case 1
• Sakura Internet case.
(http://www.sakura.ne.jp/)
• Ddos Mitigation
• Voltdb for accurate detection src-dst
• dRTBH with openflow
16
Ddos Mitigation – Case 2
• Sflow-RT application to detect
• Openflow to mitigate.
17
SDN - NAC /MSM Concept
NAC Today:
Agent 802.1x
Suplicant 802.1x
Authenticator 802.1x
Almost impossible multivendor solution.
Conceptual
SDN NAC App.
Switches, AP´s
should support SBI (Eg. Openflow)
Radius
SDN Nac App
quarantine
18
Repudiation Services
Core
Distribution
Edge
Repudiation
IPS/ IDS
with SDN Application
• Reputation(pingserver.info) Malware
• Alert administrator
19
SDN Impact on Security Architecture
Scale up... The limit will be reached someday
and Single Point of Failure....
Redundancy but What about Flow table ?
Scale Out. An external device
Who will balance the load balancer ?
20
SDN Impact on Security Architecture
• Network will execute basic filtering.
• Controller combined with a SEC APP can
centralize flow table.
• NBI interface will allow new applications
came out.
• Complex tasks (e.g. DPI) can be performed
by a separated “Service Plane” .
• Cloud Security can use SDN to scale out.
21
SDN and Security a lot of opportunities...
core
Access
cloud
DC
Enterprise
Branches
Internet
DC
Security
22
What happens if a bad guy take the control of controller ?
A. Well you are in trouble but what happened if the same bad guy take the
control of a Border router in Service Provider environment today ???
What happens if a bad guy try to D.o.S the controller ?
A. Well the bad guy should have access to management network. .. You already
in trouble before the D.o.S
There are a lot of drawbacks likewise if you look for problems in the traditional
architectures you also find a lot...
SDN Drawbacks
23
Summary
SDN unlocks constrained
networks, accelerates innovation
and drives value out of networks
-
SDN Provides Abstraction of Complexity
- Lower cost of administration
- Reduce automation risk & difficulty
Network Simplification Drives Adoption
-
SDN Enhances & Enables Network Services
- Extend life and improve performance of
‘middle boxes’
- Reduce TCO of basic services
- Improve business QoE through integration of
apps & networks
Network Innovation Drives Advantage
Q&A
Thankyou

More Related Content

PPTX
The Potential Impact of Software Defined Networking SDN on Security
PDF
SDN Security Talk - (ISC)2_3
PDF
Security Advantages of Software-Defined Networking
PPTX
Sdn pres v2-Software-defined networks
PDF
SDN Security: Two Sides of the Same Coin
DOCX
PPTX
Radware DefenseFlow-The SDN Application That Programs Networks for DoS Security
PPT
Security of software defined networking (sdn) and cognitive radio network (crn)
The Potential Impact of Software Defined Networking SDN on Security
SDN Security Talk - (ISC)2_3
Security Advantages of Software-Defined Networking
Sdn pres v2-Software-defined networks
SDN Security: Two Sides of the Same Coin
Radware DefenseFlow-The SDN Application That Programs Networks for DoS Security
Security of software defined networking (sdn) and cognitive radio network (crn)

What's hot (20)

PPTX
SDN - a new security paradigm?
PDF
Attacking SDN infrastructure: Are we ready for the next gen networking
PDF
SDN-ppt-new
ODP
OWASP Brisbane - SDN Security
PPTX
SDN Analytics & Security
PPTX
SDN: is it a solution for network security?
PDF
44CON & Ruxcon: SDN security
PPTX
Software defined networking players
PPTX
Software Defined Network (SDN)
PDF
Evaluation of Authentication Mechanisms in Control Plane Applications for Sof...
PDF
The New Landscape of Airborne Cyberattacks
PDF
IntelFlow: Toward adding Cyber Threat Intelligence to Software Defined Networ...
PDF
Solving the Visibility Gap for Effective Security
PDF
IRJET- SDN Simulation in Mininet to Provide Security Via Firewall
PDF
How Automated Vulnerability Analysis Discovered Hundreds of Android 0-days
PDF
Parrot Drones Hijacking
PPTX
ioT_SDN
PDF
DDoS Attack Detection & Mitigation in SDN
PDF
Windows Service Hardening
PPTX
What's New in StealthWatch v6.5
SDN - a new security paradigm?
Attacking SDN infrastructure: Are we ready for the next gen networking
SDN-ppt-new
OWASP Brisbane - SDN Security
SDN Analytics & Security
SDN: is it a solution for network security?
44CON & Ruxcon: SDN security
Software defined networking players
Software Defined Network (SDN)
Evaluation of Authentication Mechanisms in Control Plane Applications for Sof...
The New Landscape of Airborne Cyberattacks
IntelFlow: Toward adding Cyber Threat Intelligence to Software Defined Networ...
Solving the Visibility Gap for Effective Security
IRJET- SDN Simulation in Mininet to Provide Security Via Firewall
How Automated Vulnerability Analysis Discovered Hundreds of Android 0-days
Parrot Drones Hijacking
ioT_SDN
DDoS Attack Detection & Mitigation in SDN
Windows Service Hardening
What's New in StealthWatch v6.5
Ad

Similar to Sdn&security (20)

PPTX
Software Defined networking (SDN)
PPTX
Introduction to Software Defined Networking (SDN)
PDF
Introduction to Software Defined Networking (SDN) presentation by Warren Finc...
PPTX
The Juniper SDN Landscape
PPTX
Demystifying Software Defined Networking (SDN)
PPTX
Demystifying Software Defined Networking (SDN)
PPTX
Cis sem sdn
PDF
08 sdn system intelligence short public beijing sdn conference - 130828
PPTX
Software Defined Networks
PDF
WWT Software-Defined Networking Guide
PPTX
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...
PDF
SDN and Security: A Marriage Made in Heaven. Or Not.
PPTX
Lqsqsssssssssssssssssssssssssssssssssssq18.pptx
PDF
Provide a diagram and description of the flow table entries that can.pdf
PPTX
lect1_intro_SDN introductionpptnew1.pptx
PPTX
SDN 101: Software Defined Networking Course - Sameh Zaghloul/IBM - 2014
PDF
sdnppt.pdf
PDF
PLNOG 17 - Andrzej Jeruzal - Dell Networking OS10: sieciowy system operacyjny...
PPTX
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
PPTX
btNOG 9 presentation Introduction to Software Defined Networking
Software Defined networking (SDN)
Introduction to Software Defined Networking (SDN)
Introduction to Software Defined Networking (SDN) presentation by Warren Finc...
The Juniper SDN Landscape
Demystifying Software Defined Networking (SDN)
Demystifying Software Defined Networking (SDN)
Cis sem sdn
08 sdn system intelligence short public beijing sdn conference - 130828
Software Defined Networks
WWT Software-Defined Networking Guide
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...
SDN and Security: A Marriage Made in Heaven. Or Not.
Lqsqsssssssssssssssssssssssssssssssssssq18.pptx
Provide a diagram and description of the flow table entries that can.pdf
lect1_intro_SDN introductionpptnew1.pptx
SDN 101: Software Defined Networking Course - Sameh Zaghloul/IBM - 2014
sdnppt.pdf
PLNOG 17 - Andrzej Jeruzal - Dell Networking OS10: sieciowy system operacyjny...
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
btNOG 9 presentation Introduction to Software Defined Networking
Ad

Recently uploaded (20)

PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
KodekX | Application Modernization Development
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPT
Teaching material agriculture food technology
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Empathic Computing: Creating Shared Understanding
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
A Presentation on Artificial Intelligence
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Understanding_Digital_Forensics_Presentation.pptx
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Encapsulation_ Review paper, used for researhc scholars
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Dropbox Q2 2025 Financial Results & Investor Presentation
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Review of recent advances in non-invasive hemoglobin estimation
CIFDAQ's Market Insight: SEC Turns Pro Crypto
KodekX | Application Modernization Development
Advanced methodologies resolving dimensionality complications for autism neur...
Teaching material agriculture food technology
The AUB Centre for AI in Media Proposal.docx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Electronic commerce courselecture one. Pdf
Empathic Computing: Creating Shared Understanding
20250228 LYD VKU AI Blended-Learning.pptx
A Presentation on Artificial Intelligence
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf

Sdn&security

  • 1. SDNandSecurity August 2013 Cristiano Monteiro, Solutions Architect at HP cmonteiro@hp.com @crmonteir
  • 3. 3 Evolution of Server Architectures Proprietary Hardware Proprietary Operating Systems Proprietary Applications Innovation! Standard Intel x86-based systems Standard Operating Systems (Linux, Windows, etc) App … Standard interfaces and programming languages Standard interfaces App App
  • 4. 4 Evolution of Network Architectures Proprietary Hardware Proprietary OS OS-Integrated Features Standard “programmable” systems RoutingMCast …QoS Standard interfaces and control protocols Open interfaces and programming languages Network features (applications) Centralized Control Plane Innovation!
  • 5. 5 … In the SDN architecture, the control and data planes are decoupled, network intelligence and state are logically centralized and the underlying network infrastructure is abstracted from the applications … Open Networking Foundation on SDN Source: opennetworking.org
  • 7. 7 We need a new way to talk with Network APP Network Infrastructure Layer How the apps requirements are tied to Network Level ? • Bandwidth Resources • Isolation • Security etc. Understood !!! Security Infrastructure Layer App Guy talks to Net and Security Teams
  • 8. 8 Ability to Apply Business Logic to Network Behavior in Dynamic Fashion HP Delivers SDN to Achieve Agility Infrastructure Layer SDNArchitecture Control Layer Application Layer Separate control and data plane; abstract control plane of many devices to one Open standard-based programmatic access to infrastructure Deliver open programmable interfaces to automate orchestration of network services
  • 9. 9 Separate control and data plane; abstract control plane of many devices to one Deliver open programmable interfaces to automate orchestration of network services Open standard-based programmatic access to infrastructure Deliver open programmable interfaces to automate orchestration of network services Ability to Apply Business Logic to Network Behavior in Dynamic Fashion HP Delivers SDN to Achieve Agility Separate control and data plane; abstract control plane of many devices to one Deliver open programmable interfaces to automate orchestration of network services Open standard-based programmatic access to infrastructure Network Device Network DeviceNetwork Device Control & Data Plane Programmable Interface (e.g., OpenFlow) Network ApplicationsNetwork ApplicationsSDN Applications Business ApplicationsBusiness ApplicationsBusiness Applications (e.g., OpenStack, CloudStack) Cloud Orchestration SDN Controller Programmable Open APIs (e.g., REST) Infrastructure Layer SDNArchitecture Control Layer Application Layer
  • 10. 10 Openflow (e.g. SouthBound Interface) Both fine and coarse grain flow control possible. 10 switch controller actionsmatch rules Forward to IDS Tunnel Port Rate Limit, Forward Normal Forward Normal TCP Port 16384 TCP Port 80 from 01:23:45:67:89:ab * (wildcard)
  • 11. 11 Openstack Quantum a.k.a Neutron (E.g. Northbound Interface)
  • 12. 12 A B 2 3 4 5 61 ICMP HTTP Controller TE - APP HTTP - path 1 ICMP - path 2 Match srcpip=A,dstip=B prot=TCP dstport 80 Action In=port 1, Out=port 3 1 2 3 Match srcpip=A,dstip=B prot=ICMP ActionIn=port 1, Out=port 2 Applicatin Example : SDN Traffic Engineering
  • 14. 14 Detection : Anomaly Traffic, Signatures, Customer rings... Reaction and mitigation : Filters, Destination Filters to null “The right dose differentiates a poison and a remedy” Objective : Even under attack the customer should be online. Solutions to do that are very expensive.... Ddos Mitigation
  • 15. 15 Ddos Mitigation - Case 1 • Sakura Internet case. (http://www.sakura.ne.jp/) • Ddos Mitigation • Voltdb for accurate detection src-dst • dRTBH with openflow
  • 16. 16 Ddos Mitigation – Case 2 • Sflow-RT application to detect • Openflow to mitigate.
  • 17. 17 SDN - NAC /MSM Concept NAC Today: Agent 802.1x Suplicant 802.1x Authenticator 802.1x Almost impossible multivendor solution. Conceptual SDN NAC App. Switches, AP´s should support SBI (Eg. Openflow) Radius SDN Nac App quarantine
  • 18. 18 Repudiation Services Core Distribution Edge Repudiation IPS/ IDS with SDN Application • Reputation(pingserver.info) Malware • Alert administrator
  • 19. 19 SDN Impact on Security Architecture Scale up... The limit will be reached someday and Single Point of Failure.... Redundancy but What about Flow table ? Scale Out. An external device Who will balance the load balancer ?
  • 20. 20 SDN Impact on Security Architecture • Network will execute basic filtering. • Controller combined with a SEC APP can centralize flow table. • NBI interface will allow new applications came out. • Complex tasks (e.g. DPI) can be performed by a separated “Service Plane” . • Cloud Security can use SDN to scale out.
  • 21. 21 SDN and Security a lot of opportunities... core Access cloud DC Enterprise Branches Internet DC Security
  • 22. 22 What happens if a bad guy take the control of controller ? A. Well you are in trouble but what happened if the same bad guy take the control of a Border router in Service Provider environment today ??? What happens if a bad guy try to D.o.S the controller ? A. Well the bad guy should have access to management network. .. You already in trouble before the D.o.S There are a lot of drawbacks likewise if you look for problems in the traditional architectures you also find a lot... SDN Drawbacks
  • 23. 23 Summary SDN unlocks constrained networks, accelerates innovation and drives value out of networks - SDN Provides Abstraction of Complexity - Lower cost of administration - Reduce automation risk & difficulty Network Simplification Drives Adoption - SDN Enhances & Enables Network Services - Extend life and improve performance of ‘middle boxes’ - Reduce TCO of basic services - Improve business QoE through integration of apps & networks Network Innovation Drives Advantage