ExpertConnect - Mentoring & Discussions

You can join mentoring & discussions for Free Ask Question, Give Answer, Discuss IT Problems, Learn, and Grow

2017-10-20 14:29:00 8

CompTIA Security+

CompTIA Security+ is the first security certification IT professionals should earn. It establishes the core knowledge required of any cybersecurity role and provides a springboard to intermediate-level cybersecurity jobs.

Topic menu

2017-12-14 00:06:04 1
Profile picture of Syed Muzummil Enam
Posted: Dec 14, 2017

I have a question regarding SDN Security Risk. At the data plane layer, switches are vulnerable to denial-of-service (DoS) attacks. A malicious user can flood the switches with large payloads, causing legitimate packets to be dropped when a switch’s buffering capability is exceeded. What will be the possible ways to address this issue?

Comment (1) ·  Like (3)
Profile picture of Azhar H Khuwaja

Azhar H Khuwaja Dec 15, 2017

Thanks for this excellent question.
The answer is very similar to the one which we use for traditional network environment. We use IPS/IDS to keep an eye on various suspicious behaviors/patterns of traffic. We also need those here but in virtual format. SDN Controller should have access to these virtual security appliances in order to enforce policies and monitor suspicious/malicious traffic and block (or raise alerts) depending on the preference of network admin. In this way, we can avoid flooding which result in Denial of Service attack and we end up running out of resources.

Like (2)

Write a new comment...
Ready to post? select an option: