Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Security Challenges and Solutions in SD-WAN Deployments

View through CrossRef
Abstract Enterprise wide area network (WAN) is a private network that connects the computers and other devices across an organisation’s branch locations and the data centers. It forms the backbone of enterprise communication. Currently, multiprotocol label switching (MPLS) is commonly used to provide this service. As a recent alternative to MPLS, software-defined wide area networking (SDWAN) solutions are being introduced as an IP based cloud-networking service for enterprises. SD-WAN virtualizes the networking service and eases the complexity of configuring and managing the enterprise network by moving these tasks to software and a central controller. The introduction of new technologies causes concerns about their security. Also, this new solution is introduced as a replacement for MPLS, which has been considered secure and has been in use for more than 16 years. Thus, there is a need to analyze the security of SDWAN, which is the goal of this thesis. In this thesis, we perform a security analysis of a commercial SD-WAN solution, by finding its various attack surfaces, associated vulnerabilities and design weaknesses. We choose Nuage VNS, an SD-WAN product provided by Nuage Networks, as the analysis target. As a result, many attack surfaces and security weaknesses were found and reported, especially in the Customer Premises Equipment (CPE). In particular, we found vulnerabilities in the CPE’s secure bootstrapping method and demonstrated some attacks by exploiting them. Finally, we propose mitigation steps to avoid the attacks. The results of this thesis will help both the service provider and the SD-WAN solution vendor to know about the attack surfaces and weaknesses of SD-WAN before offering it to their customers. We also help in implementing the temporary countermeasures to mitigate the attacks. The results have been presented to the service provider and the vendor of the SDWAN product.
Title: Security Challenges and Solutions in SD-WAN Deployments
Description:
Abstract Enterprise wide area network (WAN) is a private network that connects the computers and other devices across an organisation’s branch locations and the data centers.
It forms the backbone of enterprise communication.
Currently, multiprotocol label switching (MPLS) is commonly used to provide this service.
As a recent alternative to MPLS, software-defined wide area networking (SDWAN) solutions are being introduced as an IP based cloud-networking service for enterprises.
SD-WAN virtualizes the networking service and eases the complexity of configuring and managing the enterprise network by moving these tasks to software and a central controller.
The introduction of new technologies causes concerns about their security.
Also, this new solution is introduced as a replacement for MPLS, which has been considered secure and has been in use for more than 16 years.
Thus, there is a need to analyze the security of SDWAN, which is the goal of this thesis.
In this thesis, we perform a security analysis of a commercial SD-WAN solution, by finding its various attack surfaces, associated vulnerabilities and design weaknesses.
We choose Nuage VNS, an SD-WAN product provided by Nuage Networks, as the analysis target.
As a result, many attack surfaces and security weaknesses were found and reported, especially in the Customer Premises Equipment (CPE).
In particular, we found vulnerabilities in the CPE’s secure bootstrapping method and demonstrated some attacks by exploiting them.
Finally, we propose mitigation steps to avoid the attacks.
The results of this thesis will help both the service provider and the SD-WAN solution vendor to know about the attack surfaces and weaknesses of SD-WAN before offering it to their customers.
We also help in implementing the temporary countermeasures to mitigate the attacks.
The results have been presented to the service provider and the vendor of the SDWAN product.

Related Results

Vietnam’s Marine Environmental Security: Cross-Border Challenges and Vietnam concept
Vietnam’s Marine Environmental Security: Cross-Border Challenges and Vietnam concept
Background and objective: Since beginning of the 21st century, security in the South China Sea/East Vietnam Sea has emerged as a big problem with degraded maritime environment and ...
Public budget security administration: development of primary mechanisms
Public budget security administration: development of primary mechanisms
The current state of public administration of budget security indicates its actual absence. With the extremely important role of budget security, both in the life of the country as...
Container Security in Cloud Environments
Container Security in Cloud Environments
A bstract: The widespread adoption of containers in modern software applications has introduced new challenges to se...
Advanced Kubernetes Security Architectures: Securing Multi-Cloud Deployments at Scale
Advanced Kubernetes Security Architectures: Securing Multi-Cloud Deployments at Scale
Modern enterprises increasingly deploy Kubernetes across multiple cloud providers, creating significant security challenges due to inconsistent security models and heterogeneous in...
Circular Economy: Rethinking Security Sustainability Through Ransom Project
Circular Economy: Rethinking Security Sustainability Through Ransom Project
Abstract As part of PETRONAS approach to sustainability, the organization has made more concerted effort to purposefully adopt Circular Economy (CE) across PETRONAS ...
Security as controversy: Reassembling security at Amsterdam Airport
Security as controversy: Reassembling security at Amsterdam Airport
Abstract Critical approaches to security have come to define themselves against mainstream security studies by not a priori assuming what security is, but rather ...
SECURITY REQUIREMENTS VALIDATION FOR MOBILE APPS: A SYSTEMATIC LITERATURE REVIEW
SECURITY REQUIREMENTS VALIDATION FOR MOBILE APPS: A SYSTEMATIC LITERATURE REVIEW
Security requirements are important to increase the confidence of mobile users to perform many online transactions, such as banking, booking and payment via mobile devices.  Object...
National security and public administration
National security and public administration
The article deals with the problem of national security in the contemporary world which is greatly influenced by the process of globalization and digitalization. The paper highligh...

Back to Top