Research Article

A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities

Volume: 42 Number: 2 April 30, 2024
EN

A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities

Abstract

The proliferation of software-defined networks (SDN) increases the necessity of security and forensic research in this field. Network forensics is of particular importance considering the ever-increasing traffic density and variety of devices, and SDN has great potential for improved forensic processes thanks to its ability to provide a centralized view and control of the network. This article’s motivation is the lack of a standard forensic process in SDN. The main objective of this study is to examine the differences in the forensic processes of different SDN controllers, whether the southbound interface data is sufficient for the forensic processes, and whether it is possible to choose the best controller in terms of forensics. Four of the most widely used controllers have been selected and tested under seven different scenarios to ob-serve how the results were obtained in terms of forensics. During the tests, in addition to the routine data accesses, attack preparation tools and denial-of-service attack tools were used to expand the scope. Experiments in which each scenario was applied for four different controllers demonstrated that different controllers have different characteristics in network forensics parameters, such as attack type detection, attacker information, service interruptions, packet size, and the number of packets. Experiments proved that southbound interface data is sufficient for forensic processes, different controllers have different characteristics in forensic processes, none of the most used controllers is the best to cover all forensic processes, and a standard forensic method is required for software-defined network forensics.

Keywords

References

  1. [1] Abdelaziz A, Fong AT, Gani A, Garba U, Khan S, Akhunzada A, et al. Distributed controller clustering in software defined networks. PLoS One 2017;12. [CrossRef]
  2. [2] Rawat DB, Reddy SR. Software defined networking architecture, security and energy efficiency: A survey. IEEE Commun Surv Tutorials 2017;19:325–346. [CrossRef]
  3. [3] Van Adrichem NLM, Doerr C, Kuipers FA. OpenNetMon: Network monitoring in OpenFlow software-defined networks. IEEE/IFIP NOMS 2014 - IEEE/IFIP Netw. Oper. Manag. Symp. Manag. a Softw. Defin. World, IEEE Computer Society; 2014. [CrossRef]
  4. [4] ONF White Paper, Software-Defined Networking: The New Norm for Networks, OPEN NETWORKING FOUNDATION, 2012. Available at: https://opennetworking.org/sdn- resources/whitepapers/software-defined-networking-the-new-norm-for-networks/ Accessed on Sep 5, 2022.
  5. [5] Yan Z, Zhang P, Vasilakos A V. A security and trust framework for virtualized networks and software-defined networking. Secur Commun Networks 2016;9:3059–3069. [CrossRef]
  6. [6] Chourishi D, Miri A, Milic M, Ismaeel S. Role-based multiple controllers for load balancing and security in SDN. 2015 IEEE Canada Int. Humanit. Technol. Conf. IHTC 2015, Institute of Electrical and Electronics Engineers Inc.; 2015. [CrossRef]
  7. [7] Al-Najjar A, Layeghy S, Portmann M. Pushing SDN to the end-host, network load balancing using OpenFlow. 2016 IEEE Int. Conf. Pervasive Comput. Commun. Work. PerCom Work. 2016, Institute of Electrical and Electronics Engineers Inc.; 2016. [CrossRef]
  8. [8] Kreutz D, Ramos FMV, Verissimo PE, Rothenberg CE, Azodolmolky S, Uhlig S. Software-defined networking: A comprehensive survey. Proc IEEE 2015;103:14–76. [CrossRef]

Details

Primary Language

English

Subjects

Computer Software

Journal Section

Research Article

Authors

Publication Date

April 30, 2024

Submission Date

July 6, 2022

Acceptance Date

December 17, 2022

Published in Issue

Year 2024 Volume: 42 Number: 2

APA
Çil, A., & Demirci, M. (2024). A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities. Sigma Journal of Engineering and Natural Sciences, 42(2), 425-437. https://doi.org/10.14744/sigma.2022.00107
AMA
1.Çil A, Demirci M. A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities. SIGMA. 2024;42(2):425-437. doi:10.14744/sigma.2022.00107
Chicago
Çil, Altuğ, and Mehmet Demirci. 2024. “A Comparative Analysis of Software-Defined Network Controllers in Terms of Network Forensics Processes and Capabilities”. Sigma Journal of Engineering and Natural Sciences 42 (2): 425-37. https://doi.org/10.14744/sigma.2022.00107.
EndNote
Çil A, Demirci M (April 1, 2024) A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities. Sigma Journal of Engineering and Natural Sciences 42 2 425–437.
IEEE
[1]A. Çil and M. Demirci, “A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities”, SIGMA, vol. 42, no. 2, pp. 425–437, Apr. 2024, doi: 10.14744/sigma.2022.00107.
ISNAD
Çil, Altuğ - Demirci, Mehmet. “A Comparative Analysis of Software-Defined Network Controllers in Terms of Network Forensics Processes and Capabilities”. Sigma Journal of Engineering and Natural Sciences 42/2 (April 1, 2024): 425-437. https://doi.org/10.14744/sigma.2022.00107.
JAMA
1.Çil A, Demirci M. A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities. SIGMA. 2024;42:425–437.
MLA
Çil, Altuğ, and Mehmet Demirci. “A Comparative Analysis of Software-Defined Network Controllers in Terms of Network Forensics Processes and Capabilities”. Sigma Journal of Engineering and Natural Sciences, vol. 42, no. 2, Apr. 2024, pp. 425-37, doi:10.14744/sigma.2022.00107.
Vancouver
1.Altuğ Çil, Mehmet Demirci. A comparative analysis of software-defined network controllers in terms of network forensics processes and capabilities. SIGMA. 2024 Apr. 1;42(2):425-37. doi:10.14744/sigma.2022.00107

IMPORTANT NOTE: JOURNAL SUBMISSION LINK https://eds.yildiz.edu.tr/sigma/