Software Defined Networking has put the accent on the implementation of effective, sophisticated algorithms for the control plane, running on centralized devices. Pure centralization, however, also introduces inefficiencies and limitations in many scenarios, often negatively affecting security. Network applications could benefit from data plane programmability, e.g. implementing the increasingly popular P4 language. In this paper, we show that P4-enabled switches can run simple yet significant tasks that enhance the cooperation with the control plane, improving traffic analysis functionalities of practical relevance for security monitoring purposes. We also show how this P4- based solutions can be integrated into an SDN architecture acting as an Intrusion Detection System.

A Security Monitoring Architecture based on Data Plane Programmability / Amir Al Sadi, Davide Berardi, Franco Callegati, Andrea Melis, Marco Prandini. - ELETTRONICO. - (2021), pp. 1-6. (Intervento presentato al convegno Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit) tenutosi a Porto (PT) nel 8-11 June 2021) [10.1109/EuCNC/6GSummit51104.2021.9482549].

A Security Monitoring Architecture based on Data Plane Programmability

Amir Al Sadi
Membro del Collaboration Group
;
Davide Berardi
Membro del Collaboration Group
;
Franco Callegati
Conceptualization
;
Andrea Melis
Membro del Collaboration Group
;
Marco Prandini
Conceptualization
2021

Abstract

Software Defined Networking has put the accent on the implementation of effective, sophisticated algorithms for the control plane, running on centralized devices. Pure centralization, however, also introduces inefficiencies and limitations in many scenarios, often negatively affecting security. Network applications could benefit from data plane programmability, e.g. implementing the increasingly popular P4 language. In this paper, we show that P4-enabled switches can run simple yet significant tasks that enhance the cooperation with the control plane, improving traffic analysis functionalities of practical relevance for security monitoring purposes. We also show how this P4- based solutions can be integrated into an SDN architecture acting as an Intrusion Detection System.
2021
2021 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit)
1
6
A Security Monitoring Architecture based on Data Plane Programmability / Amir Al Sadi, Davide Berardi, Franco Callegati, Andrea Melis, Marco Prandini. - ELETTRONICO. - (2021), pp. 1-6. (Intervento presentato al convegno Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit) tenutosi a Porto (PT) nel 8-11 June 2021) [10.1109/EuCNC/6GSummit51104.2021.9482549].
Amir Al Sadi, Davide Berardi, Franco Callegati, Andrea Melis, Marco Prandini
File in questo prodotto:
Eventuali allegati, non sono esposti

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11585/904879
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 5
  • ???jsp.display-item.citation.isi??? 4
social impact