Aplicação de Políticas de Segurança em SDN (OpenDaylight): mTLS e GBP contra Ataques DoS/MITM em Simulação
PDF (Español (España))
EPUB (Español (España))

Palavras-chave

Redes Definidas por Software; OpenDaylight; OpenFlow; Política Baseada em Grupos; mTLS; Negação de Serviço; Detecção de Intrusão.

Como Citar

Narváez Chiliguano, G. G., Andrade Paredes, R. O., & Cuenca Tapia, J. P. (2025). Aplicação de Políticas de Segurança em SDN (OpenDaylight): mTLS e GBP contra Ataques DoS/MITM em Simulação. Religación, 11(49), e2601587. https://doi.org/10.46652/rgn.v11i49.1587

Resumo

As Redes Definidas por Software (SDN) centralizam e programam o controle de tráfego, mas introduzem vulnerabilidades críticas no controlador. Em um ambiente simulado com Mininet e OpenDaylight, foram identificadas fragilidades (credenciais padrão "admin", comunicação sem criptografia e manipulação de regras de fluxo). Em seguida, políticas de segurança foram aplicadas (regras OpenFlow via RESTCONF, Group-Based Policy e mTLS com certificados X.509), e sua eficácia contra ataques DoS e MITM foi avaliada por meio de Wireshark, Ettercap e logs do controlador. Ao longo de quatro períodos (T1–T4), observou-se uma diminuição na latência relativa (~45%→~30%), disponibilidade estável (≈90–95%) e um aumento na taxa de detecção (~40%→~45%). Um teste t para amostras pareadas (α=0,05) indicou melhorias estatisticamente significantes. Os resultados demonstram que mTLS + GBP + OpenFlow fortalecem a confidencialidade, a integridade e a disponibilidade na rede SDN simulada.

https://doi.org/10.46652/rgn.v11i49.1587
PDF (Español (España))
EPUB (Español (España))

Referências

Arévalo-Herrera, J., Camargo Mendoza, J., & Martínez Torre, J. I. (2025). Assessing SDN controller vulnerabilities: A survey on attack typologies, detection mechanisms, controller selection, and dataset application in machine learning. Wireless Personal Communications, 140, 739–775. https://doi.org/10.1007/s11277-025-11748-w

Mabood, N., Tariq, N., Khan, F. A., & Ashraf, M. (2025). A comprehensive survey on software defined networking (SDN) security. En M. Arif, A. Jaffar, & O. Geman, (eds.). Computing and emerging technologies (ICCET 2023). Springer, Cham. https://doi.org/10.1007/978-3-031-77617-5_18

Mejía Viteri, J. T., Gonzales Valero, M. I., Fernández Torres, A. del R., & Crespo Torres, N. M. (2024). Seguridad contra ataques DDoS en los entornos SDN con inteligencia artificial. Revista Metropolitana de Ciencias, 7(3). https://doi.org/10.33262/rmc.v7i3.2844

Mudgal, A., Verma, A., Singh, M., Sahoo, K. S., Elmroth, E., & Bhuyan, M. (2024). FloRa: Flow table low-rate overflow reconnaissance and detection in SDN. IEEE Transactions on Network and Service Management, 21(6), 6670–6683. https://doi.org/10.1109/TNSM.2024.3446178

Ohri, P., & Guha Neogi, S. (2022). Software-defined networking security challenges and solutions: A comprehensive survey. International Journal of Computing and Digital Systems, 12(1), 383–400. https://doi.org/10.12785/ijcds/120131

Open Networking Foundation. (2025). OpenFlow 2.0. https://n9.cl/rw7o3

Ouedraogo Rakissaga, W. A., Omar, H. H., & Kouraogo, P. J. (2025). Software Defined Networks: Strengths, weaknesses, and resilience to failures. Engineering, 17(1), 20–35. https://doi.org/10.4236/eng.2025.171002

Shahzad, M., Rizvi, S., Khan, T. A., Ahmad, S., Siddiqui, M. S., Chen, J., Li, X., Wang, Y., Kumar, N., Patel, R., García, S., Fernández, L., Müller, H., Schmidt, P., Ivanov, A., Silva, C., Kim, Y., & Al-Mistarihi, M. (2025). An exhaustive parametric analysis for securing SDN through traditional, AI/ML, and blockchain approaches: A systematic review. International Journal of Networked and Distributed Computing, 13(1). https://doi.org/10.1007/s44227-024-00055-8

Swileh, M. N., & Zhang, S. (2024). Unseen attack detection in software-defined networking using a BERT-based large language model. arXiv. https://arxiv.org/abs/2412.06239

Wang, H. (2025). A zero-trust security model applied in SDN intelligent network. SPIE Digital Library. https://doi.org/10.1117/12.3058610

Creative Commons License
This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.

Downloads

Não há dados estatísticos.