& cplSiteName &

OpenDaylight Establishes Security Team

Mitch Wagner
12/19/2014
50%
50%

The OpenDaylight Project Technical Steering Committee has set up an official security response team following disclosure of a serious vulnerability in the open source SDN controller that went unaddressed four months after it was initially disclosed.

The committee also approved Helium-SR1.1 (Service Release 1.1), which incorporates previously released patches for the security problem, according to an email from Colin Dixon, chair of the OpenDaylight Technical Steering Committee, who posted to the group's mailing list.

The organization "established an official security response team charged with developing more formal internal processes for dealing with security," Dixon stated in his email.

The "Netdump" security flaw was discovered in August by Gregory Pickett, part of the managed security services group for Hellfire Security. The vulnerability allows remote attackers to take control of an OpenDaylight SDN network. Pickett says he tried unsuccessfully for months to get the OpenDaylight Project to pay attention. They finally did, and patched it, this week. (See OpenDaylight Patches 'Serious Vulnerability' – After Four Months.)

Despite the delay, Pickett credits the OpenDaylight project for behaving responsibly. "It was just a break-down in communication," he says in an email to Light Reading. "As soon as they became aware of the issue, they [the developers] moved on it. And they are working on a process to make sure that it doesn't happen again. So, yes, I would say very responsible."

Two of the companies who use OpenDaylight code in their software say it's not a problem for their customers.

"Brocade Vyatta Controller customers have been alerted to the vulnerability and an emergency patch is being delivered shortly," stated Brocade Communications Systems Inc. (Nasdaq: BRCD) distinguished engineer Tom Nadeau in an email to Light Reading. (See Brocade Debuts OpenDaylight SDN Controller.)


Want to know more about SDN? Visit Light Reading's SDN Technology content channel.


ConteXtream audits its software and closes security holes "before they are closed in the open source distribution. This is where a carrier-grade vendor comes in," says co-founder Sharon Barkai in an email to Light Reading. Also, ConteXtream federates OpenDaylight, "which means if the customer wants to use more experimentally controlled code for specific entities, it does not jeopardize the entire distributed system." (See ConteXtream Launches OpenDaylight-Based SDN Fabric for NFV.)

Pickett also discovered separate security vulnerabilities in the Big Switch Networks -sponsored Floodlight open source controller. But Floodlight has no security by design, says a Big Switch spokeswoman. The security is added when the open source project gets converted to product.

"Floodlight is not meant to be used outside of a testbed, which is one reason why no security features are implemented. [Big Switch] is very transparent about this, why it is set up this way, and how it's a differentiation around its commercial product," the spokeswoman said. "Floodlight was built to do what it does -- security was always something that users could choose to add on as part of their configuration. By contrast, Big Switch Network's commercial products have authenticated REST APIs and in-depth Role-Based Access Control (RBAC) features to provide enterprise-level security." (See Big Switch Intros Flagship Big Cloud Fabric – At Last.)

For a directory of SDN controllers, including those based on OpenDaylight code, see Who Does What: SDN Controllers.

— Mitch Wagner, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profileFollow me on Facebook, West Coast Bureau Chief, Light Reading. Got a tip about SDN or NFV? Send it to wagner@lightreading.com.

(2)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
Susan Fourtané
50%
50%
Susan Fourtané,
User Rank: Blogger
12/22/2014 | 12:57:07 AM
Re: security teams at more open source projects...
mhh, How right you are. Open source can be a great thing but it also requires a lot of responsibility in security terms. As you point out, this year has been awful in the security department. The only option is to improve security from every possible angle. -Susan
mhhf1ve
50%
50%
mhhf1ve,
User Rank: Light Sabre
12/19/2014 | 5:00:39 PM
security teams at more open source projects...
This year has seen an awful lot of security vulnerablities found in open source code... so I wonder if more open source projects are going to start taking security more seriously. It's hard to get volunteer programmers to really cover all the bases sometimes, but security might be getting more important as folks see how widespread open source code is... and are surprised by where the flaws end up.
From The Founder
Cisco's Conrad Clemson, recently promoted to head up the company's Service Provider Apps & Platforms developments, talks to Light Reading's Founder and CEO Steve Saunders about how he's bringing cloud video, mobile and virtualization together to empower network operators.
Flash Poll
Live Streaming Video
Charting the CSP's Future
Six different communications service providers join to debate their visions of the future CSP, following a landmark presentation from AT&T on its massive virtualization efforts and a look back on where the telecom industry has been and where it's going from two industry veterans.
LRTV Custom TV
How Intel Is Powering the 5G Era

3|29|17   |     |   (0) comments


Light Reading tours a series of 5G "super demos" so see how Intel envisions the 5G-connected future. We take a look at a prototype connected BMW, a light pole with environmental sensors that provides 5G wireless to a smart home and a fully untethered virtual reality experience.
LRTV Custom TV
Source Photonics CEO Doug Wright Talks About the Future of Source Photonics

3|29|17   |     |   (0) comments


Source Photonics' CEO, Doug Wright, talks to Light Reading about how the company is continuously investing in its operations to meet not only its customers' current technology demands but also to deliver their next-generation technology needs.
LRTV Custom TV
Live Demo: DevOps in Service Chains & 5G Network Slices PoC

3|29|17   |     |   (0) comments


Executives from PoC collaborating companies – Patrick Waldemar, VP and Head of Technology at Telenor Research, John Healy, VP of the Datacenter Network Solutions Group at Intel, Vincent Spinelli, SVP of Global Sales and Marketing at RIFT.io, Mats Eriksson, CEO and co-founder of Arctos Labs, and Mats Nordlund, CEO and co-founder of Netrounds – review ...
LRTV Documentaries
The Year of Fat & Skinny Bundles

3|29|17   |   21:06   |   (0) comments


In this fireside chat, Roku's Andrew Ferrone predicts that 2017 will be the year of multichannel OTT video bundles and spells out other trends in the OTT and pay-TV markets.
LRTV Huawei Video Resource Center
BBWF 2016: Orange Poland's Next-Gen Central Office

3|28|17   |     |   (0) comments


Introduction to Orange Poland's legacy next-generation central office solution.
LRTV Custom TV
Viavi at OFC 2017

3|28|17   |   4:15   |   (0) comments


Light Reading's Editor-in-Chief Craig Matsumoto reports from the Viavi booth at OFC and gets an update on the 400G testing market from Tom Fawcett, VP and GM of LAB & Production. At this year's event, Viavi won three awards from Lightwave magazine and showcased an interoperability demo with Ethernet Alliance and Finisar.
LRTV Custom TV
Connecting the Entire Home With DOCSIS 3.1

3|28|17   |   3:58:   |   (0) comments


Hitron Technologies had the first cable modem certified for DOCSIS 3.1 and already has over 120,000 units in the field. Greg Fisher, CTO of Hitron, provides an update on his company's rollout of new gateways and why he thinks DOCSIS 3.1 will continue to drive value for operators into 2017 and beyond.
LRTV Interviews
Amazon Prime's Hand of God Creator on Producing for OTT

3|28|17   |     |   (1) comment


Ben Watkins is the creator, writer and producer of Hand of God, a series on Amazon Prime. At Light Reading's Cable Next-Gen conference in Denver, he explained the advantages of producing for an OTT platform versus traditional TV.
LRTV Custom TV
How Metrological Keeps Cable Customers on the Couch

3|28|17   |     |   (0) comments


Metrological offers an open source solution that reduces the time it takes cable operators to integrate OTT content into the linear television viewing experience.
LRTV Documentaries
The ABC of OTT

3|28|17   |     |   (0) comments


At Light Reading's Cable Next-Gen conference in Denver, Ben Watkins, creator of Amazon Prime's Hand of God show, explained how producing content for an OTT platform differs from producing content for traditional TV.
Shades of Ray
Why Analytics Is the Tech World's Digital Glue

3|27|17   |   02:20   |   (0) comments


It was obvious at the massive annual CeBIT enterprise tech trade show that the foundation for tech innovation right now is real-time analytics.
LRTV Custom TV
CommScope – Meeting the Demands of Tomorrow's Networks

3|24|17   |     |   (0) comments


Phil Sorksy, Vice President International at CommScope, discusses addressing the challenges faced by service providers today, and as future trends emerge.
Upcoming Live Events
May 15-17, 2017, Austin Convention Center, Austin, TX
May 15, 2017, Austin Convention Center - Austin, TX
June 6, 2017, The Joule Hotel, Dallas, TX
All Upcoming Live Events
Infographics
With the mobile ecosystem becoming increasingly vulnerable to security threats, AdaptiveMobile has laid out some of the key considerations for the wireless community.
Hot Topics
FTTH No Slam Dunk for Cable
Carol Wilson, Editor-at-large, 3/23/2017
Unlocking China's $194B Telecom Market
Robert Clark, 3/27/2017
WiCipedia: Supergirls, No More Excuses & Media Monitoring
Eryn Leavens, Special Features & Copy Editor, 3/24/2017
Welcome to the Wild West of Privacy
Carol Wilson, Editor-at-large, 3/24/2017
Like Us on Facebook
Twitter Feed
BETWEEN THE CEOs - Executive Interviews
TEOCO Founder and CEO Atul Jain talks to Light Reading Founder and CEO Steve Saunders about the challenges around cost control and service monetization in the mobile and IoT sectors.
At MWC 2017, Qualcomm's CTO Matt Grob talks to Light Reading's CEO and Founder Steve Saunders about the progress being made in the development of the technologies and standards that will underpin 5G.
Animals with Phones
Working From Home Doesn't Work for Everyone Click Here
You shouldn't nap on your keyboard, for instance.
Live Digital Audio

Playing it safe can only get you so far. Sometimes the biggest bets have the biggest payouts, and that is true in your career as well. For this radio show, Caroline Chan, general manager of the 5G Infrastructure Division of the Network Platform Group at Intel, will share her own personal story of how she successfully took big bets to build a successful career, as well as offer advice on how you can do the same. We’ll cover everything from how to overcome fear and manage risk, how to be prepared for where technology is going in the future and how to structure your career in a way to ensure you keep progressing. Chan, a seasoned telecom veteran and effective risk taker herself, will also leave plenty of time to answer all your questions live on the air.