VLDB 2026 Research / reviewers in the wild / expert
Kallol Krishna Karmakar
dblp:180/8361
· DBLP profile ↗
25ranked-venue papers
7as first author
13since 2021 · last 2025
0000-0002-2768-2051ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 5 first-author · 5 since 2021Security and privacy · 4 · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Security-aware data provenance for multi-domain software-defined networks
Visal Dam, Fariha Tasmin Jaigirdar, Kallol Krishna Karmakar, Adnan Anwar |
Comput. Secur. | 3 |
| 2025 | Achieving Robustness and Dropout Fairness with Hierarchical Federated Learning in Smart Grid InfrastructuresabstractWith the recent rapid expansion of the smart grid infrastructure paving the way for greater integration of computer and network technologies within the power grid, it has become well suited for the application of machine learning techniques. However, machine learning requires vast amounts of data, which within the smart grid setting can reveal great amounts of personal details of the individuals using the grid. This work considers the application of a variant of distributed machine learning, federated learning, which enhances data privacy. We propose a Smart Grid Hierarchical Federated Learning (SGHFL) framework, which is tuned to common smart grid architectures in the real world. We demonstrate how our SGHFL framework improves client dropout and poisoning robustness, using relatively lightweight models suitable for devices with limited computational capability. We provide theoretical justification underlying our design and have evaluated our algorithms and framework with three datasets/environments of progressively increasing practicality. We have also compared our framework with relevant works. Cody Lewis, Vijay Varadharajan, Nasimul Noman, Udaya Kiran Tupakula, Kallol Krishna Karmakar |
ACM Trans. Cyber Phys. Syst. | 5 |
| 2024 | The WMDP Benchmark: Measuring and Reducing Malicious Use with UnlearningabstractThe White House Executive Order on Artificial Intelligence highlights the risks of large language models (LLMs) empowering malicious actors in developing biological, cyber, and chemical weapons. To measure these risks, government institutions and major AI labs are developing evaluations for hazardous capabilities in LLMs. However, current evaluations are private and restricted to a narrow range of malicious use scenarios, which limits further research into reducing malicious use. To fill these gaps, we release the Weapons of Mass Destruction Proxy (WMDP) benchmark, a dataset of 3,668 multiple-choice questions that serve as a proxy measurement of hazardous knowledge in biosecurity, cybersecurity, and chemical security. To guide progress on unlearning, we develop RMU, a state-of-the-art unlearning method based on controlling model representations. RMU reduces model performance on WMDP while maintaining general capabilities in areas such as biology and computer science, suggesting that unlearning may be a concrete path towards reducing malicious use from LLMs. We release our benchmark and code publicly at https://wmdp.ai. Nathaniel Li, Alexander Pan, Anjali Gopal, Summer Yue, Daniel Berrios, Alice Gatti, Justin D. Li, Ann-Kathrin Dombrowski, Shashwat Goel, Gabriel Mukobi, Nathan Helm-Burger, Rassin Lababidi, Lennart Justen, Andrew B. Liu, Isabelle Barrass, Oliver Zhang, Xiaoyuan Zhu, Rishub Tamirisa, Bhrugu Bharathi, Ariel Herbert-Voss, Cort B. Breuer, Andy Zou, Mantas Mazeika, Zifan Wang 0001, Palash Oswal, Weiran Lin, Adam A. Hunt, Justin Tienken-Harder, Kevin Y. Shih, Kemper Talley, John Guan, Ian Steneker, David Campbell, Brad Jokubaitis, Steven Basart, Stephen Fitz, Ponnurangam Kumaraguru, Kallol Krishna Karmakar, Udaya Kiran Tupakula, Vijay Varadharajan, Yan Shoshitaishvili, Jimmy Ba, Kevin M. Esvelt, Alexandr Wang, Dan Hendrycks |
ICML | 39 |
| 2024 | Techniques for Enhancing Security in Industrial Control SystemsabstractIncreasingly Industrial Control Systems (ICS) systems are being connected to the Internet to minimise the operational costs and provide additional flexibility. These control systems such as the ones used in power grids, manufacturing and utilities operate continually and have long lifespans measured in decades rather than years as in the case of Information Technology (IT) systems. Such industrial control systems require uninterrupted and safe operation. However, they can be vulnerable to a variety of attacks, as successful attacks on critical control infrastructures could have devastating consequences to the safety of human lives as well as a nation’s security and prosperity. Furthermore, there can be a range of attacks that can target ICS and it is not easy to secure these systems against all known attacks let alone unknown ones. In this paper, we propose a software enabled security architecture using Software Defined Networking (SDN) and Network Function Virtualisation (NFV) that can enhance the capability to secure industrial control systems. We have designed such an SDN/NFV enabled security architecture and developed a Control System Security Application (CSSA) in SDN Controller for enhancing security in ICS by achieving real time situational awareness and dynamic policy-driven decision making across the network infrastructure. In particular, CSSA can be used for establishing secure path for end-to-end communication between devices and also deal against certain specific attacks namely denial of service attacks, from unpatched vulnerable control system components and securing the communication flows from the legacy devices that do not support any security functionality. We also discuss how CSSA provides reliable paths for safety critical messages in control systems. We discuss the prototype implementation of the proposed architecture and the results obtained from our analysis. Vijay Varadharajan, Udaya Kiran Tupakula, Kallol Krishna Karmakar |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2023 | A trust-aware openflow switching framework for software defined networks (SDN)abstractSoftware Defined Networks (SDN) and Network Function Virtualisation (NFV) are prime driving technologies behind 5G and Beyond 5G (B5G) communications. The network control intelligence segregation in the SDN infrastructure enables dynamic network features (such as dynamic end-to-end management of security and quality of service (QoS)) offering significantly improved network performance. Even if one assumes that the centralised SDN controller can be security hardened and hence can be trusted, a fundamental challenge in such networks is that the data plane and switching devices are susceptible to cyberattacks. A malicious adversary can compromise them during run-time making them unreliable for secure and trusted communications. Furthermore, the controller communicating with OpenFlow switching devices is unable to accurately assess the state of the switching devices, which serves as the communication base for NFVs in 5G networks. Vulnerable switching devices can put the whole 5G network infrastructure at risk. Hence, there is a clear need for the controller and the management layer to determine the trustworthiness of the switching devices at run-time. The current trend is for many such devices to deploy trusted computing functionality such as Trusted Platform Module (TPM) or Software Guard Extension (SGx) to achieve local as well as remote attestation. In this paper, we present a dynamic trust management framework for evaluating the trustworthiness of the OpenFlow switching devices deployed in the SDN based networks. We formulate device properties that need to be assessed to determine the trust status of the device. We develop a trust enhanced security architecture which can be used to evaluate the trustworthiness of devices and determine their deployment in the provision of network services. The proposed framework uses subjective logic based techniques to derive trust levels of the switching devices at run-time, which are then used by the architecture to make trust enhanced decisions on the provision of network services. A prototype implementation of the proposed architecture is described, which demonstrates how the trustworthiness of the OpenFlow devices are assessed at run-time. The paper concludes with the performance and security analysis of the implemented trust enhanced architecture services. Kallol Krishna Karmakar, Vijay Varadharajan, Michael Hitchens, Udaya Kiran Tupakula, Prajna Sariputra |
Comput. Networks | 1 |
| 2022 | SDPM: A Secure Smart Device Provisioning and Monitoring Service Architecture for Smart Network InfrastructureabstractThe Internet of Things (IoT) are becoming a prevalent part of our society offering operational flexibility and convenience. However, insecure provisioning makes the IoT devices susceptible to various cyberattacks. For instance, mal-provisioned devices may leak sensitive information allowing the attackers to eavesdrop or disrupt communication infrastructures. Furthermore, compromised devices can act as zombies to intensify the scale of the attack. Hence, we need secure device provisioning services which can counteract such attacks and adverse circumstances. This article proposes a secure smart device provisioning and monitoring service architecture (SDPM) for smart network infrastructures, such as IoT-enabled smart home or office and Industrial IoT infrastructures. Our architecture allows the provisioning of devices in such a way that the malicious devices can be controlled and their activities using a dynamic policy-based approach. SDPM introduces an IoT device ontology for device registration and authentication and uses the ontology to construct device category and service-specific policies. SDPM provides a fine granular pre and post condition-based policies to provision securely the IoT devices and control their runtime operations. Furthermore, SDPM utilizes the digital twin concept, to monitor dynamically the security status of IoT devices at runtime. The policies associated with a device’s twin enables the SDPM to automate security capabilities, such as device firmware updating and patching for security vulnerabilities. Kallol Krishna Karmakar, Vijay Varadharajan, Pete Speirs, Michael Hitchens, Aron Robertson |
IEEE Internet Things J. | 1 |
| 2022 | Toward a Trust Aware Network Slice-Based Service Provision in Virtualized InfrastructuresabstractFuture communication networks such as 5G are expected to support end-to-end delivery of services for several vertical markets with diverging requirements. Network slicing is a key construct that is used to provide end to end logical virtual networks running on a common virtualised infrastructure, which are mutually isolated. Having different network slices operating over the same 5G infrastructure creates several challenges in security and trust. This paper addresses the fundamental issue of trust of a network slice. It presents a trust model and property-based trust attestation mechanisms, which can be used to evaluate the trust of the virtual network functions that compose the network slice. The proposed model helps to determine the trust of the virtual network functions, as well as the properties that should be satisfied by the virtual platforms (both at boot and run time), on which these network functions are deployed for them to be trusted. We present a logic-based language that defines simple rules for the specification of properties and the conditions under which these properties need to be satisfied for trusted virtualized platforms. The proposed trust model and mechanisms enable the service providers to determine the trustworthiness of the network services as well as the users to develop trustworthy applications. We have developed a trust management architecture that enables the service providers to determine the trustworthiness of the network slices providing the network services. We have implemented a prototype of the trust management architecture using the Open Source MANO Platform and presented the performance results. The results show that our trust mechanisms cause only a slight reduction in the performance of network slices over virtualized infrastructure. We have also discussed how the proposed architecture can be used to detect and mitigate the impact of malicious virtual network functions in a dynamic manner. Vijay Varadharajan, Kallol Krishna Karmakar, Udaya Kiran Tupakula, Michael Hitchens |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2021 | Software Enabled Security Architecture and Mechanisms for Securing 5G Network ServicesabstractThe 5G network systems are evolving and have complex network infrastructures. There is a great deal of work in this area focused on meeting the stringent service requirements for the 5G networks. Within this context, security requirements play a critical role as 5G networks can support a range of services such as healthcare services, financial and critical infrastructures. 3GPP and ETSI have been developing security frameworks for 5G networks. Our work in 5G security has been focusing on the design of security architecture and mechanisms enabling dynamic establishment of secure and trusted end to end services as well as development of mechanisms to proactively detect and mitigate security attacks in virtualised network infrastructures. The focus of this paper is on the latter, namely the facilities and mechanisms, and the design of a security architecture providing facilities and mechanisms to detect and mitigate specific security attacks. We have developed a simplified version of the security architecture using Software Defined Networks (SDN) and Network Function Virtualisation (NFV) technologies. The specific security functions developed in this architecture can be directly integrated into the 5G core network facilities enhancing its security. Vijay Varadharajan, Udaya Kiran Tupakula, Kallol Krishna Karmakar |
NetSoft | 3 |
| 2021 | FedDICE: A Ransomware Spread Detection in a Distributed Integrated Clinical Environment Using Federated Learning and SDN Based Mitigation
Chandra Thapa, Kallol Krishna Karmakar, Alberto Huertas Celdrán, Seyit Ahmet Çamtepe, Vijay Varadharajan, Surya Nepal |
QSHINE | 2 |
| 2021 | Techniques for Securing Control Systems from AttacksabstractIncreasingly Industrial Control Systems (ICS) systems are being connected to the Internet to minimise the operational costs and provide additional flexibility. These control systems such as the ones used in power grids, manufacturing and utilities operate continually and have long lifespans measured in decades rather than years as in the case of IT systems. Such industrial control systems require uninterrupted and safe operation. However, they can be vulnerable to a variety of attacks, as successful attacks on critical control infrastructures could have devastating consequences to the safety of human lives as well as a nation's security and prosperity. Furthermore, there can be a range of attacks that can target ICS and it is not easy to secure these systems against all known attacks let alone unknown ones. In this paper, we propose a software enabled security architecture using Software Defined Networking (SDN) and Network Function Virtualisation (NFV) that can enhance the capability to secure industrial control systems. We have designed such an SDN/NFV enabled security architecture and developed a Control System Security Application (CSSA) in SDN Controller for enhancing security in ICS against certain specific attacks namely denial of service attacks, from unpatched vulnerable control system components and securing the communication flows from the legacy devices that do not support any security functionality. In this paper, we discuss the prototype implementation of the proposed architecture and the results obtained from our analysis. Udaya Kiran Tupakula, Vijay Varadharajan, Kallol Krishna Karmakar |
TrustCom | 3 |
| 2021 | Techniques for Securing 5G Network Services from attacksabstractThe 5G network systems are evolving and have complex network infrastructures. There is a great deal of work in this area focused on meeting the stringent service requirements for the 5G networks. Within this context, security requirements play a critical role as 5G networks can support a range of services such as healthcare services, financial and critical infrastructures. 3GPP and ETSI have been developing security frameworks for 5G networks. Our work in 5G security has been focusing on the design of security architecture and mechanisms enabling dynamic establishment of secure and trusted end to end services as well as development of mechanisms to proactively detect and mitigate security attacks in virtualised network infrastructures. The focus of this paper is on the latter, namely the facilities and mechanisms, and the design of a security architecture providing facilities and mechanisms to detect and mitigate specific security attacks. We have developed and implemented a simplified version of the security architecture using Software Defined Networks (SDN) and Network Function Virtualisation (NFV) technologies. The specific security functions developed in this architecture can be directly integrated into the 5G core network facilities enhancing its security. We describe the design and implementation of the security architecture and demonstrate how it can efficiently mitigate specific types of attacks. Vijay Varadharajan, Udaya Kiran Tupakula, Kallol Krishna Karmakar |
TrustCom | 3 |
| 2021 | SDN-Enabled Secure IoT ArchitectureabstractThe Internet of Things (IoT) is increasingly being used in applications ranging from precision agriculture to critical national infrastructure by deploying a large number of resource-constrained devices in hostile environments. These devices are being exploited to launch attacks in cyber systems. As a result, security has become a significant concern in the design of IoT-based applications. In this article, we present a security architecture for IoT networks by leveraging the underlying features supported by software-defined networks (SDNs). Our security architecture not only restricts network access to authenticated IoT devices but also enforces fine granular policies to secure the flows in the IoT network infrastructure. The authentication is achieved using a lightweight protocol to authenticate IoT devices. Authorization is achieved using a dynamic policy driven approach. Such an integrated security approach involving authentication of IoT devices and enables authorized flows to protect IoT networks from malicious IoT devices and attacks. We have implemented and validated our architecture using ONOS SDN Controller and Raspbian Virtual Machines, and demonstrated how the proposed security mechanisms can counteract malware packet injection, DDoS attacks using Mirai, spoofing/masquerading, and man-in-the-middle attacks. An analysis of the security and performance of the proposed security mechanisms and their applications is presented in this article. Kallol Krishna Karmakar, Vijay Varadharajan, Surya Nepal, Udaya Kiran Tupakula |
IEEE Internet Things J. | 1 |
| 2021 | Detecting and mitigating cyberattacks using software defined networks for integrated clinical environmentsabstractAbstract The evolution of integrated clinical environments (ICE) and the future generations of mobile networks brings to reality the hospitals of the future and their innovative clinical scenarios. The mobile edge computing paradigm together with network function virtualization techniques and the software-defined networking paradigm enable self-management, adaptability, and security of medical devices and data management processes making up clinical environments. However, the logical centralized approach of the SDN control plane and its protocols introduce new vulnerabilities which affect the security of the network infrastructure and the patients’ safety. The paper at hand proposes an SDN/NFV-based architecture for the mobile edge computing infrastructure to detect and mitigate cybersecurity attacks exploiting SDN vulnerabilities of ICE in real time and on-demand. A motivating example and experiments presented in this paper demonstrate the feasibility of of the proposed architecture in a realistic clinical scenario. Alberto Huertas Celdrán, Kallol Krishna Karmakar, Félix Gómez Mármol, Vijay Varadharajan |
Peer-to-Peer Netw. Appl. | 2 |
| 2020 | Towards a Security Enhanced Virtualised Network Infrastructure for Internet of Medical Things (IoMT)abstractInternet of Medical Things (IoMT) are getting popular in the smart healthcare domain. These devices are resource-constrained and are vulnerable to attack. As the IoMTs are connected to the healthcare network infrastructure, it becomes the primary target of the adversary due to weak security and privacy measures. In this regard, this paper proposes a security architecture for smart healthcare network infrastructures. The architecture uses various security components or services that are developed and deployed as virtual network functions. This makes the security architecture ready for future network frameworks such as OpenMANO. Besides, in this security architecture, only authenticated and trusted IoMTs serve the patients along with an encryption-based communication protocol, thus creating a secure, privacy-preserving and trusted healthcare network infrastructure. Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula, Surya Nepal, Chandra Thapa |
NetSoft | 1 |
| 2020 | Attack Detection on the Software Defined Networking SwitchesabstractSoftware Defined Networking (SDN) is disruptive networking technology which adopts a centralised framework to facilitate fine-grained network management. However security in SDN is still in its infancy and there is need for significant work to deal with different attacks in SDN. In this paper we discuss some of the possible attacks on SDN switches and propose techniques for detecting the attacks on switches. We have developed a Switch Security Application (SSA)for SDN Controller which makes use of trusted computing technology and some additional components for detecting attacks on the switches. In particular TPM attestation is used to ensure that switches are in trusted state during boot time before configuring the flow rules on the switches. The additional components are used for storing and validating messages related to the flow rule configuration of the switches. The stored information is used for generating a trusted report on the expected flow rules in the switches and using this information for validating the flow rules that are actually enforced in the switches. If there is any variation to flow rules that are enforced in the switches compared to the expected flow rules by the SSA, then, the switch is considered to be under attack and an alert is raised to the SDN Administrator. The administrator can isolate the switch from network or make use of trusted report for restoring the flow rules in the switches. We will also present a prototype implementation of our technique. Udaya Kiran Tupakula, Vijay Varadharajan, Kallol Krishna Karmakar |
NetSoft | 3 |
| 2020 | Towards a Dynamic Policy Enhanced Integrated Security Architecture for SDN InfrastructureabstractEnterprise networks are increasingly moving towards Software Defined Networking, which is becoming a major trend in the networking arena. With the increased popularity of SDN, there is a greater need for security measures for protecting the enterprise networks. This paper focuses on the design and implementation of an integrated security architecture for SDN based enterprise networks. The integrated security architecture uses a policy-based approach to coordinate different security mechanisms to detect and counteract a range of security attacks in the SDN. A distinguishing characteristic of the proposed architecture is its ability to deal with dynamic changes in the security attacks as well as changes in trust associated with the network devices in the infrastructure. The adaptability of the proposed architecture to dynamic changes is achieved by having feedback between the various security components/mechanisms in the architecture and managing them using a dynamic policy framework. The paper describes the prototype implementation of the proposed architecture and presents security and performance analysis for different attack scenarios. We believe that the proposed integrated security architecture provides a significant step towards achieving a secure SDN for enterprises. Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula, Michael Hitchens |
NOMS | 1 |
| 2020 | Alleviating Heterogeneity in SDN-IoT Networks to Maintain QoS and Enhance SecurityabstractSoftware-defined networks (SDNs) offer unique and attractive solutions to solve challenging management issues in Internet of Things (IoT)-based large-scale multi-technological networks. SDN-IoT network collaboration is innovative and attractive but expected to be extremely heterogeneous in future generation IoT systems. For example, multi-technology network, network externality, and nodes heterogeneity in SDN-IoT may seriously affect the flow or application-specific quality-of-service (QoS) requirements. Furthermore, it highly influences security adoption in a network of interconnected IoT nodes. We observe that both QoS and security are interdependent and nonnegligible factors, thus we emphasize that in order to alleviate heterogeneity it is inevitable to study both these factors hand to hand (or vice versa). With this aim, first, we discuss significant and reasonable cases to encourage researchers to study QoS and security integrally in order to alleviate heterogeneity at SDN-IoT control plane. Second, we propose a framework which successfully transforms the m heterogeneous controllers to n homogeneous controller groups. The key metric of our observation and analysis is the SDN controller's response time. Following this, to validate our approach, we use the mathematical model and a proof of concept (PoC) in a virtual SDN ecosystem is demonstrated. From performance evaluation, we observe that the proposed framework significantly alleviates heterogeneity which helps to maintain QoS and enhance security. This fundamental analysis will enable network security individuals to deal heterogeneity, QoS, and security, of SDN-IoT, in more successful and promising ways. Keshav Sood, Kallol Krishna Karmakar, Shui Yu 0001, Vijay Varadharajan, Shiva Raj Pokhrel, Yong Xiang 0001 |
IEEE Internet Things J. | 2 |
| 2019 | Access Control Based Dynamic Path Establishment for Securing Flows from the User Devices with Different Security Clearance
Udaya Kiran Tupakula, Vijay Varadharajan, Kallol Krishna Karmakar |
AINA | 3 |
| 2019 | SDN-Capable IoT Last-Miles: Design ChallengesabstractWe propose to redesign SDN control in IoT lastmiles so as to extend the capability from edge routers to devices (end-node things enabled with SDN capabilities). Our approach put forward existing and new challenges that are impossible to be resolved using the seminal approaches directly. The main challenges we identify are: scalability of sensor nodes/things, maintaining the security of the system, and fulfilling the Quality of Service (QoS) requirement of all IoT applications. Firstly, we elaborate and discuss the aforementioned critical and fundamental challenges that require immediate investigations. Secondly, we propose a policy-driven framework for secure routing and conduct performance modeling and analysis. Further, in the QoS context, we have proposed an intent-based flow offloading scheme to meet the flow-specific QoS requirements. More importantly, we have developed an analysis by modeling TCP-based flows over WiFi, thus forming the required SDN-IoT network, by using mathematics as a tool for reasoning our challenges. With new insights from our analysis, the feasibility of the proposed approach is validated using factors such as path set-up time in SDN-IoT networks, SDN controller/devices throughputs, packets losses and response time of the controller. Keshav Sood, Shiva Raj Pokhrel, Kallol Krishna Karmakar, Vijay Varadharajan, Shui Yu 0001 |
GLOBECOM | 3 |
| 2019 | SDN Enabled Secure IoT Architecture
Kallol Krishna Karmakar, Vijay Varadharajan, Surya Nepal, Udaya Kiran Tupakula |
IM | 1 |
| 2019 | A Policy-Based Security Architecture for Software-Defined NetworksabstractAs networks expand in size and complexity, they pose greater administrative and management challenges. Software-defined networks (SDNs) offer a promising approach to meeting some of these challenges. In this paper, we propose a policy-driven security architecture for securing end-to-end services across multiple SDN domains. We develop a language-based approach to design security policies that are relevant for securing SDN services and communications. We describe the policy language and its use in specifying security policies to control the flow of information in a multi-domain SDN. We demonstrate the specification of fine-grained security policies based on a variety of attributes, such as parameters associated with users and devices/switches, context information, such as location and routing information, and services accessed in SDN as well as security attributes associated with the switches and controllers in different domains. An important feature of our architecture is its ability to specify path- and flow-based security policies that are significant for securing end-to-end services in SDNs. We describe the design and the implementation of our proposed policy-based security architecture and demonstrate its use in scenarios involving both intra- and inter-domain communications with multiple SDN controllers. We analyze the performance characteristics of our architecture as well as discuss how our architecture is able to counteract various security attacks. The dynamic security policy-based approach and the distribution of corresponding security capabilities intelligently as a service layer that enables flow-based security enforcement and protection of multitude of network devices against attacks are important contributions of this paper. Vijay Varadharajan, Kallol Krishna Karmakar, Udaya Kiran Tupakula, Michael Hitchens |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | Towards QoS and Security in Software-Driven Heterogeneous Autonomous NetworksabstractAutonomous Networks has a potential to solve complex and critical management issues in large scale multi- technological networks. Further, the novel paradigms, i.e., Software-Defined Networks (SDN) and Network Function Vir- tualization (NFV) offer unique and attractive solutions for Autonomous Networks or Systems (AS). However, despite of these attractive features, we observed two critical issues in this interlinked multi-technology domain. Firstly, the network externality and nodes heterogeneity seriously effected the flow specific Quality of Service (QoS). Secondly, it influenced se- curity adoption in an network of interconnected nodes. We observed that QoS and security both are non-negligible and inter-dependent factors. This motivates us to investigate solution towards a) alleviating the SDN network heterogeneity at control layer, and b) to strengthen the network security after alleviating the heterogeneity. In this research effort, we have attempted to alleviate the first issue. Firstly, significant and reasonable examples have been cited to motivate researchers to study QoS and security hand-to-hand. Secondly, a theoretical high level frame work has been proposed with the aim to transform the N heterogeneous controllers to n homogeneous controller groups. Following this, we have demonstrated that our approximation method to transform heterogeneous systems to homogeneous groups works well even at high degree of heterogeneity in the network. We have shown our theoretical analysis results using Matlab. Following this, we have shown the Proof of Concept (PoC) of our approach in SDN-NFV ecosystem using Mininet. This early analysis will help researchers to address heterogeneity and security in more effective ways. Keshav Sood, Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula, Shui Yu 0001 |
GLOBECOM | 2 |
| 2017 | Securing communication in multiple Autonomous System domains with Software Defined NetworkingabstractIn this paper we proposed policy based security architecture for securing the communication in multiple Autonomous System (AS) domains with Software Defined Networks (SDN). We will present a high level overview of the architecture and detail discussion on some of the important components for securing the communication in multiple AS domains. A key component of the security architecture is the specification of security policies that are to be enforced on the SDN communications whether they are intra or inter-domain. We will present example scenarios to demonstrate the operation of the security architecture to enable end-to-end secure communication within a single AS domain and for multiple AS domains. We have justified the model using ONOS controller. Vijay Varadharajan, Kallol Krishna Karmakar, Udaya Kiran Tupakula |
IM | 2 |
| 2017 | SDN-based Dynamic Policy Specification and Enforcement for Provisioning SECaaS in Cloud
Udaya Kiran Tupakula, Vijay Varadharajan, Kallol Krishna Karmakar |
WISE (2) | 3 |
| 2016 | On the Design and Implementation of a Security Architecture for End to End Services in Software Defined NetworksabstractIn this paper, we propose a policy driven security architecture for securing end to end services across multiple autonomous domain based SDN environment. We develop a language based approach to designing a range of security policies that are relevant for SDN services and communications. The design of a security architecture that enables secure routing of packets based on the specified security policies in the SDN Controller is described. Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula |
LCN | 1 |