This document proposes enhancing security in OpenFlow networks. It discusses:
1) OpenFlow currently has security flaws like lack of authentication, encryption, and intrusion detection that can compromise the network.
2) The proposal is to use a network intrusion detection system as a middlebox to monitor traffic at the OpenFlow controller and detect suspicious activity.
3) Additional mechanisms like authentication, encryption, and forensics are needed to fully secure OpenFlow networks against vulnerabilities introduced by the separation of the data and control planes.