{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T14:16:17Z","timestamp":1761401777819},"reference-count":38,"publisher":"Wiley","issue":"13","license":[{"start":{"date-parts":[[2015,10,26]],"date-time":"2015-10-26T00:00:00Z","timestamp":1445817600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security Comm Networks"],"published-print":{"date-parts":[[2016,9,10]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The advancement of software defined networking (SDN) is redefining traditional computer networking architecture. The role of the control plane of SDN is of such importance that SDNs are referred to as network operating systems (OSs). However, the robustness and security of the network OS has been overlooked. In this paper, we report three main issues pertaining to network OSs. First, we identified vulnerabilities that could be exploited by malicious or buggy applications running on network OSs. We also identified four major attack vectors that could undermine network OS operations: denial of service, global data manipulation, control plane poisoning, and system shell execution. Further, it was demonstrated that real\u2010world attacks can be launched on commonly used network OSs without significant effort. Second, we present a method to address the attacks by analyzing network applications running on network OSs to identify their behavioral features, which enabled the extraction of a permission set for each network application. Based on this work, a permission\u2010based malicious network application detector was introduced, which examines the permission set of each application and prevents it from executing without permission. Our system shows almost no performance overhead. Copyright \u00a9 2015 John Wiley &amp; Sons, Ltd.<\/jats:p>","DOI":"10.1002\/sec.1369","type":"journal-article","created":{"date-parts":[[2015,10,26]],"date-time":"2015-10-26T07:51:30Z","timestamp":1445845890000},"page":"1971-1982","source":"Crossref","is-referenced-by-count":19,"title":["Vulnerabilities of network OS and mitigation with state\u2010based permission system"],"prefix":"10.1002","volume":"9","author":[{"given":"Jiseong","family":"Noh","sequence":"first","affiliation":[{"name":"Graduate School of Information Security, School of Computing Korea Advanced Institute of Science and Technology  Daejeon Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Seunghyeon","family":"Lee","sequence":"additional","affiliation":[{"name":"Graduate School of Information Security, School of Computing Korea Advanced Institute of Science and Technology  Daejeon Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jaehyun","family":"Park","sequence":"additional","affiliation":[{"name":"Graduate School of Information Security, School of Computing Korea Advanced Institute of Science and Technology  Daejeon Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Seungwon","family":"Shin","sequence":"additional","affiliation":[{"name":"Graduate School of Information Security, School of Computing Korea Advanced Institute of Science and Technology  Daejeon Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Brent Byunghoon","family":"Kang","sequence":"additional","affiliation":[{"name":"Graduate School of Information Security, School of Computing Korea Advanced Institute of Science and Technology  Daejeon Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","published-online":{"date-parts":[[2015,10,26]]},"reference":[{"key":"e_1_2_10_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1384609.1384625"},{"key":"e_1_2_10_3_1","unstructured":"MccauleyJ.POX: a Python\u2010based OpenFlow controller. Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/www.noxrepo.org\/pox\/about-pox\/[Accessed on 2 October 2015]."},{"key":"e_1_2_10_4_1","unstructured":"BigS.Floodlight openflow controller. Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/www.projectfloodlight.org\/floodlight\/[Accessed on 2 October 2015]."},{"key":"e_1_2_10_5_1","unstructured":"OpenFlowHub.BEACON. Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/www.openflowhub.org\/display\/Beacon[Accessed on 2 October 2015]."},{"key":"e_1_2_10_6_1","unstructured":"FoundationL.OpenDaylight. Available from:https:\/\/2.zoppoz.workers.dev:443\/https\/www.opendaylight.org\/[2 October 2015]."},{"key":"e_1_2_10_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2377677.2377766"},{"key":"e_1_2_10_8_1","doi-asserted-by":"crossref","unstructured":"BragaR MotaE PassitoA.Lightweight ddos flooding attack detection using nox\/openflow 2010 IEEE 35th Conference on Local Computer Networks (LCN) Denver CO USA 2010;408\u2013415.","DOI":"10.1109\/LCN.2010.5735752"},{"key":"e_1_2_10_9_1","doi-asserted-by":"crossref","unstructured":"JainS KumarA MandalS et al.B4: experience with a globally\u2010deployed software defined WAN Proceedings of the ACM SIGCOMM 2013 Conference on SIGCOMM.ACM Hong Kong China 2013;3\u201314.","DOI":"10.1145\/2486001.2486019"},{"key":"e_1_2_10_10_1","unstructured":"HeiligerJ.Building efficient data centers with the open compute project 2011. Available from:https:\/\/ www.facebook.com\/notes\/facebook\u2010engineering\/building\u2010efficient\u2010data\u2010centers\u2010with\u2010the\u2010open\u2010compute\u2010project\/10150144039563920[Accessed on 2 October 2015]."},{"key":"e_1_2_10_11_1","doi-asserted-by":"crossref","unstructured":"DixitA HaoF MukherjeeS LakshmanTV KompellaR.Towards an elastic distributed SDN controller.Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking.ACM Hong Kong China 2013;7\u201312.","DOI":"10.1145\/2491185.2491193"},{"key":"e_1_2_10_12_1","unstructured":"KoponenT CasadoM GudeN et al.Onix: a distributed control platform for large\u2010scale production networks Proceedings of the 9th USENIX conference on Operating systems design and implementation.Vancouver BC Canada 2010;1\u20136."},{"key":"e_1_2_10_13_1","unstructured":"TootoonchianA GanjaliY.Hyperflow: a distributed control plane for openflow Proceedings of the 2010 Internet Network Management Conference on Research on Enterprise Networking.USENIX Association San Jose CA USA 2010;3\u20133."},{"key":"e_1_2_10_14_1","doi-asserted-by":"crossref","unstructured":"KreutzD RamosF VerissimoP.Towards secure and dependable software\u2010defined networks Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking.ACM Hong Kong China 2013;55\u201360.","DOI":"10.1145\/2491185.2491199"},{"key":"e_1_2_10_15_1","doi-asserted-by":"crossref","unstructured":"WenX ChenY HuC ShiC WangY.Towards a secure controller platform for openflow applications Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking.ACM Hong Kong China 2013;171\u2013172.","DOI":"10.1145\/2491185.2491212"},{"key":"e_1_2_10_16_1","doi-asserted-by":"crossref","unstructured":"ShinS SongY LeeT LeeS ChungJ PorrasP YegneswaranV NohJ KangBB.Rosemary: a robust secure and high\u2010performance network operating system Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security.ACM Scottsdale AZ USA 2014;78\u201389.","DOI":"10.1145\/2660267.2660353"},{"key":"e_1_2_10_17_1","unstructured":"MelvinM.Network Computing. Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/www.networkcomputing.com\/networking\/can\u2010sdn\u2010adoption\u2010solve\u2010real\u2010world\u2010problems\/a\/d\u2010id\/1005791[Accessed on 2 October 2015]."},{"key":"e_1_2_10_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1355734.1355746"},{"key":"e_1_2_10_19_1","unstructured":"HP.SDN App Store. Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/h17007.www1.hp.com\/us\/en\/networking\/solutions\/technology\/sdn\/devcenter\/index.aspx#tab=TAB1[Accessed on October 2 2015]."},{"key":"e_1_2_10_20_1","unstructured":"Mininet.Rapid prototyping for software defined networks. Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/yuba.stanford.edu\/foswiki\/bin\/view\/OpenFlow\/Mininet\/[Accessed on 2 October 2015]."},{"key":"e_1_2_10_21_1","doi-asserted-by":"crossref","unstructured":"MonacoM MichelO KellerE.Applying operating system principles to sdn controller design Proceedings of the Twelfth ACM Workshop on Hot Topics in Networks.ACM College Park MD USA 2013;2.","DOI":"10.1145\/2535771.2535789"},{"key":"e_1_2_10_22_1","unstructured":"ShinS PorrasP YegneswaranV FongM GuG TysonM.Fresco: modular composable security services for software\u2010defined networks Proceedings of 20th Annual Network & Distributed System Security Symposium.San Diego CA USA 2013."},{"key":"e_1_2_10_23_1","doi-asserted-by":"crossref","unstructured":"ShinS GuG.Attacking software\u2010defined networks: a first feasibility study Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking.ACM Hong Kong China 2013;165\u2013166.","DOI":"10.1145\/2491185.2491220"},{"key":"e_1_2_10_24_1","doi-asserted-by":"crossref","unstructured":"Kl\u00f6tiR.Openflow: a security analysis 8th Workshop on Secure Network Protocols (NPSEC 2013) G\u00f6ttingen Germany 2013;1\u20136.","DOI":"10.1109\/ICNP.2013.6733671"},{"key":"e_1_2_10_25_1","doi-asserted-by":"crossref","unstructured":"Scott\u2010HaywardS O'CallaghanG SezerS.Sdn security: a survey 2013 IEEE SDN for Future Networks and Services (SDN4FNS).IEEE Trento Italy 2013;1\u20137.","DOI":"10.1109\/SDN4FNS.2013.6702553"},{"key":"e_1_2_10_26_1","doi-asserted-by":"crossref","unstructured":"ShalimovA ZuikovD ZimarinaD PashkovV SmelianskyR.Advanced study of SDN\/openflow controllers Proceedings of the 9th Central & Eastern European Software Engineering Conference in Russia.ACM Moscow Russia 2013;1.","DOI":"10.1145\/2556610.2556621"},{"key":"e_1_2_10_27_1","doi-asserted-by":"crossref","unstructured":"PorrasP ShinS YegneswaranV FongM TysonM GuG.A security enforcement kernel for OpenFlow networks Proceedings of the first workshop on Hot topics in Software Defined Networking.Helsinki Finland 2012;121\u2013126.","DOI":"10.1145\/2342441.2342466"},{"key":"e_1_2_10_28_1","unstructured":"OpenFlowSec.org.SEFloodlight. Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/www.openflowsec.org\/Home.html[Accessed on 2 October 2015]."},{"key":"e_1_2_10_29_1","unstructured":"CaniniM VenzanoD PeresiniP KosticD RexfordJ.A NICE way to test OpenFlow applications Proceedings of the 9th USENIX conference on Networked Systems Design and Implementation.San Jose CA USA 2012;127\u2013140."},{"key":"e_1_2_10_30_1","unstructured":"McGillicuddyS.SDN security issues: how secure is the SDN stack?Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/searchsdn.techtarget.com\/news\/2240214438\/SDN\u2010security\u2010issues\u2010How\u2010secure\u2010is\u2010the\u2010SDN\u2010stack[Accessed on 2 October 2015]."},{"key":"e_1_2_10_31_1","unstructured":"WeinbergN.Is SDN your next security nightmare?Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/www.networkworld.com\/news\/2014\/022814\u2010rsa\u2010sdn\u2010security\u2010279298.html[Accessed on 2 October 2015]."},{"key":"e_1_2_10_32_1","unstructured":"PrinceB.Beware SDN security risks experts warn. Available from:www.networkcomputing.com\/ next-generation-data-center\/news\/networking\/beware-sdn-security-risks-experts-warn\/240166081[Accessed on 2 October 2015]."},{"key":"e_1_2_10_33_1","unstructured":"Android Open\u00a0Source Project.What is Android?Introduction to Android. Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/developer.android.com\/guide\/index.html[Accessed on 2 October 2015."},{"key":"e_1_2_10_34_1","doi-asserted-by":"crossref","unstructured":"BarreraD KayacikHG vanOorschotPC SomayajiA.A methodology for empirical analysis of permission\u2010based security models and its application to android Proceedings of the 17th ACM Conference on Computer and Communications Security.ACM Chicago IL USA 2010;73\u201384.","DOI":"10.1145\/1866307.1866317"},{"key":"e_1_2_10_35_1","doi-asserted-by":"crossref","unstructured":"FeltAP ChinE HannaS SongD WagnerD.Android permissions demystified Proceedings of the 18th ACM Conference on Computer and Communications Security.ACM Chicago IL USA 2011;627\u2013638.","DOI":"10.1145\/2046707.2046779"},{"key":"e_1_2_10_36_1","doi-asserted-by":"crossref","unstructured":"AuKWY ZhouYF HuangZ LieD.Pscout: analyzing the android permission specification Proceedings of the 2012 ACM Conference on Computer and Communications Security.ACM Raleigh NC USA 2012;217\u2013228.","DOI":"10.1145\/2382196.2382222"},{"key":"e_1_2_10_37_1","unstructured":"SmalleyS CraigR.Security enhanced (SE) android: bringing flexible MAC to Android Proceedings of 20th Annual Network & Distributed System Security Symposium San Diego CA USA 2013."},{"key":"e_1_2_10_38_1","doi-asserted-by":"crossref","unstructured":"Scott\u2010HaywardS KaneC SezerS.Operationcheckpoint: SDN application control 2014 IEEE 22nd International Conference on Network Protocols (ICNP).IEEE The Research Triangle NC USA 2014;618\u2013623.","DOI":"10.1109\/ICNP.2014.98"},{"key":"e_1_2_10_39_1","doi-asserted-by":"crossref","unstructured":"EnglerDR KaashoekMF O'TooleJW.Exokernel: An Operating System Architecture for Application\u2010level Resource Management Proceedings of the fifteenth ACM symposium on Operating systems principles.Copper Mountain CO USA 1995;251\u2013266.","DOI":"10.1145\/224057.224076"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fsec.1369","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/sec.1369","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,3]],"date-time":"2023-09-03T00:32:05Z","timestamp":1693701125000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/10.1002\/sec.1369"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,10,26]]},"references-count":38,"journal-issue":{"issue":"13","published-print":{"date-parts":[[2016,9,10]]}},"alternative-id":["10.1002\/sec.1369"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1002\/sec.1369","archive":["Portico"],"relation":{},"ISSN":["1939-0114","1939-0122"],"issn-type":[{"value":"1939-0114","type":"print"},{"value":"1939-0122","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,10,26]]}}}