SDNsec: Forwarding Accountability for the SDN Data Plane

被引:0
|
作者
Sasaki, Takayuki [1 ]
Pappas, Christos [2 ]
Lee, Taeho [2 ]
Hoefler, Torsten [2 ]
Perrig, Adrian [2 ]
机构
[1] NEC Corp Ltd, Tokyo, Japan
[2] Swiss Fed Inst Technol, Zurich, Switzerland
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN promises to make networks more flexible, programmable, and easier to manage. Inherent security problems in SDN today, however, pose a threat to the promised benefits. First, the network operator lacks tools to proactively ensure that policies will be followed or to reactively inspect the behavior of the network. Second, the distributed nature of state updates at the data plane leads to inconsistent network behavior during reconfigurations. Third, the large flow space makes the data plane susceptible to state exhaustion attacks. This paper presents SDNsec, an SDN security extension that provides forwarding accountability for the SDN data plane. Forwarding rules are encoded in the packet, ensuring consistent network behavior during reconfigurations and limiting state exhaustion attacks due to table lookups. Symmetric-key cryptography is used to protect the integrity of the forwarding rules and enforce them at each switch. A complementary path validation mechanism allows the controller to reactively examine the actual path taken by the packets. Furthermore, we present mechanisms for secure link-failure recovery.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] Dynamic Packet Forwarding Verification in SDN
    Li, Qi
    Zou, Xiaoyue
    Huang, Qun
    Zheng, Jing
    Lee, Patrick P. C.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (06) : 915 - 929
  • [22] Traffic Management Applications for Stateful SDN Data Plane
    Cascone, Carmelo
    Pollini, Luca
    Sanvito, Davide
    Capone, Antonio
    2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 85 - 90
  • [23] A technique to monitor threats in SDN data plane computation
    Desgeorges, Loic
    Georges, Jean-Philippe
    Divoux, Thierry
    2021 IEEE 22ND INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (IEEE HPSR), 2021,
  • [24] Measuring the Consistency Between Data and Control Plane in SDN
    Lei, Kai
    Lin, Guanjie
    Zhang, Meimei
    Li, Keke
    Li, Qi
    Jing, Xiaojun
    Wang, Peng
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2023, 31 (02) : 511 - 525
  • [25] Network Anti-Spoofing with SDN Data plane
    Afek, Yehuda
    Bremler-Barr, Anat
    Shafir, Lior
    IEEE INFOCOM 2017 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, 2017,
  • [26] FAIR: Forwarding Accountability for Internet Reputability
    Pappas, Christos
    Reischuk, Raphael M.
    Perrig, Adrian
    2015 IEEE 23RD INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2015, : 189 - 200
  • [27] Securing SDN Southbound and Data Plane Communication with IBC
    Lam, JunHuy
    Lee, Sang-Gon
    Lee, Hoon-Jae
    Oktian, Yustus Eko
    MOBILE INFORMATION SYSTEMS, 2016, 2016
  • [28] Detecting IP Prefix Mismatches on SDN Data Plane
    Tung, Shu-Po
    Lin, Yu-Min
    Chang, Keng-Lun
    Hsiao, Hsu-Chun
    Kim, Tiffany Hyun-Jin
    2024 33RD INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, ICCCN 2024, 2024,
  • [29] Toward migration to SDN: Generating SDN Forwarding Rules by Decision Tree
    Youssef, Sawsan
    Rysavy, Ondrej
    2023 26TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS, ICIN, 2023,
  • [30] Forwarding plane flooding
    Apostolopoulos, G
    EIGHTH IEEE INTERNATIONAL SYMPOSIUM ON COMPUTERS AND COMMUNICATION, VOLS I AND II, PROCEEDINGS, 2003, : 963 - 968