Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Security is the Missing Link in SDN
Articles

Security is the Missing Link in SDN

Brian A. McHenryBy Brian A. McHenryFebruary 23, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In the onward rush to software-defined things in the cloud, it seems the concept of network function virtualization (NFV) is beginning to catch up with the more mature (and some might say commoditized) server and application virtualization technologies. With NFV reaching stages of maturity, and controller solutions emerging from seemingly every vendor, what’s holding back the full-on adoption of Software-Defined Networking (SDN)? Well, there is a missing link in the chain, namely security.

The promise of SDN is the ability to define data paths via the network that are optimized for scale and efficiency. Tried and true technologies such as routing protocols seem positively rigid by comparison to SDN and NFV. However, even when the entire data path is completely fluid at the network layer, some services reside on the network that aren’t defined by route and switch policies.

With security in mind, these services include everything from IPS services to load-balancing and decryption services, most of which are stateful. So, via SDN, we can dynamically shift a traffic flow through a path with the right bandwidth, connecting two or more endpoints, but if vital services relating to security aren’t also dynamically configured, the data transaction will never be successful. Ultimately, a network is about successful data transmission, and these security service gaps make the full promise of SDN impossible to realize.

Stateful security services are not marketed as “SDN-ready” or as “software-defined security” (SDS). (By the way, security vendors better hurry because the storage people are claiming “SDS,” too.) Most of these services already host an API, in addition to the more commonly-used CLI and GUI management options. In fact, many vendors are hurrying to update and enhance these APIs to make them more readily programmable and robust, usually by converting to REST and ensuring feature-parity with CLI command options. When evaluating our current security services, whether network firewall, IPS, web application firewall (WAF), or other service, these are important aspects of the API that should be inspected. It may be as straightforward as upgrading the firmware operating system of the security appliance to obtain a more robust, modern API capable of supporting our goals for SDN automation and orchestration.

Given that some stateful security services can be dynamically programmed to add an ACL rule or policy via such an API, what are the next steps?

First, if we haven’t already selected an SDN controller or orchestration suite, we must research whether a supported plug-in or integration exists. Many security technologies have focused on vetting integrations for the most popular SDN solutions such as Cisco ACI, VMware NSX, and OpenFlow, to name only a few. The integration may be as simple as a plug-in to install, or as seemingly complex as a script that must be customized. In either case, not all such integrations may cover how we leverage the security services in our infrastructure, so we must be prepared to customize and extend these integrations or build them ourselves to suit.

The second part, which may be more challenging for us as an industry, is finding the skills within our ranks to build these solutions. Do we have the folks with programming and scripting skills on our security or networking teams? If not, are we able to “borrow” resources from our friends in application development? Who are the individuals on staff who can quickly ramp these new skills? These types of conversations between network, security, and development teams could be the necessary catalyst to an entire DevOps movement within the organization.

On the subject of DevOps, one of the keys to success in creating some notion of software-defined security services may well be thinking smaller. Last week, Jeff Sussna (@jeffsussna) wrote a very intriguing article on micro-services segmentation needing DevOps to succeed, and I would agree. We are seeing a convergence of many ideas (cloud, SDN, DevOps, microservices, etc.) which have the potential to be incredibly powerful in the world of security, altering how the infosec team is perceived within most organizations.

In the world of information technology, the security people are often seen as the “Department of No,” a gating factor to progress or deployment of a new system or service. In the software-defined world of things, we have the opportunity to alter that perception by enabling the adoption of SDN and simplifying the configuration and management of security services. While the skills shortage may be killing defense in depth, there’s an opportunity for information security professionals to enhance their own careers while simultaneously improving their organization’s security posture.

Can SDN and SDS be combined to revive the defense-in-depth concept? Clearly, the potential exists to create more focused and adaptable security services via the concepts of DevOps, microservices, and integration with SDN. The tools exist today on various security service platforms to build these types of solutions, so the obstacle is not one of tools or technology. The first challenge for many will be bringing various organizations together for collaboration: security, networking, development, and perhaps others. The next challenge will be identifying the necessary skills to build the integrations from the gathered stakeholders. With the expanding threat landscape, we cannot afford to abandon defense-in-depth strategies. Rather, we must leverage these new architectural and design concepts to make these old strategies more effective.

[su_box title=”About Brian A. McHenry” style=”noise” box_color=”#0e0d0d”]

Brian_McHenryBio: As a Security Solutions Architect at F5 Networks, Brian McHenry focuses on web application and network security. McHenry acts as a liaison between customers, the F5 sales team, and the F5 product teams, providing a hands-on, real-world perspective. Prior to joining F5 in 2008, McHenry, a self-described “IT generalist”, held leadership positions within a variety of technology organizations, ranging from startups to major financial services firms.

Twitter: @bamchenry[/su_box]

 

Brian_McHenry
Brian A. McHenry

As a Senior Security Solutions Architect at F5 Networks, Brian McHenry focuses on web application and network security. McHenry acts as a liaison between customers and F5 product teams, providing a hands-on, real-world perspective. He is a regular contributor on InformationSecurityBuzz.com, a co-founder of BSidesNYC, and a speaker at AppSecUSA, BC Aware Day, GoSec Montreal, and the Central Ohio Infosec Summit, among others. Prior to joining F5 in 2008, McHenry, a self-described IT generalist, held leadership positions within a variety of technology organizations, ranging from startups to major financial services firms.

  • Brian A. McHenry
    The WAF Is Not Enough
  • Brian A. McHenry
    Access Management, With A Side Order Of Identity
  • Brian A. McHenry
    The Internet of Thingbots
  • Brian A. McHenry
    Black Hat USA 2017: Bigger and Better (?)

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

June 2, 20263 Mins Read

CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet

June 1, 20265 Mins Read

Artificial intelligence and elections: When an election is annulled because of TikTok

June 1, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}