@inproceedings{bee17dfea68949f28e60e906c39dafef,
title = "BAGUETTE: Towards a Secure and Cost-effective Switch Upgrade in Hybrid Software-Defined Networks",
abstract = "Software-Defined Networking (SDN), providing flexible controlling and monitoring mechanisms that simplifies network management, is becoming prevalent in recent years. However, replacing all legacy network devices with SDN-capable devices is cost-prohibitive. One practical approach for the SDN deployment is to incrementally upgrade a few legacy devices to SDN devices. The network, which consists of legacy and SDN devices, is called a hybrid SDN. Existing hybrid SDN deployment schemes do not consider the security impact of device deployment. They use the same type of devices to upgrade, and upgraded devices could be compromised if an attacker controls one SDN device by leveraging its vulnerabilities.In this paper, we consider this security issue in the hybrid SDN deployment and present the Secure and Cost-effective Switch Upgrade (SCESU) problem. The SCESU problem aims to upgrade a few network devices to satisfy the security requirement by using multiple SDN switch types with a minimal upgrade cost. The complexity of the SCESU problem comes from common vulnerabilities shared among different types of SDN devices and attack propagations among network nodes. To efficiently solve the problem, we propose the BAGUETTE algorithm to judiciously choose and upgrade critical legacy switches with selected SDN devices. Simulation results show that BAGUETTE achieves up to about 92.1 security enhancement compared with legacy network and reduces to 11.1 cost of the securest deployment.",
keywords = "Hybrid SDN deployment, SDN, attack mitigation., security",
author = "Wendi Feng and Zehua Guo and Chuanchang Liu and Yueming Zheng and Meng Wang and Bo Cheng and Junliang Chen",
note = "Publisher Copyright: {\textcopyright} 2020 IEEE.; 2020 IEEE International Conference on Communications, ICC 2020 ; Conference date: 07-06-2020 Through 11-06-2020",
year = "2020",
month = jun,
doi = "10.1109/ICC40277.2020.9148928",
language = "English",
series = "IEEE International Conference on Communications",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
booktitle = "2020 IEEE International Conference on Communications, ICC 2020 - Proceedings",
address = "United States",
}