Fast IP Hopping Randomization to Secure Hop-by-Hop Access in SDN

被引:38
|
作者
Chang, Sang-Yoon [1 ]
Park, Younghee [2 ]
Babu, Bhavana Babu Ashok [2 ]
机构
[1] Univ Colorado, Comp Sci, Colorado Springs, CO 80918 USA
[2] San Jose State Univ, Comp Engn, San Jose, CA 95192 USA
基金
美国国家科学基金会;
关键词
Moving target defense; access randomization; network synchronization; IP address control; software-defined network (SDN); data plane security; network security; DENIAL-OF-SERVICE; AUTHENTICATION; MECHANISM; DEFENSE; FILTER; FLOW;
D O I
10.1109/TNSM.2018.2889842
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Moving target defense (MTD) is useful for thwarting network reconnaissance and preventing unauthorized access. While previous research in MTD focuses on protecting the endnodes, we leverage software-defined networking to implement MTD on the data-plane switches, which significantly decreases the controller communication overhead and enables quicker defense response to reduce the attack impact. This paper not only randomizes the IP addresses for MTD but also uses the IP addresses for synchronization across the nodes in the networking path by generating hash-chain-based synchronization signatures. Our scheme is practical as it builds on and encodes the existing IP addresses for randomization to construct a modular solution independent to the routing/flow rule implementation and does not incur additional networking overhead except for the seed distribution (which can occur offline). Our scheme is also effective (the attacker's required cost to achieve timely network reconnaissance increases by more than an order of magnitude than the previous state-of-the-art having the controller actuate the MTD randomization) and scalable (the relative overhead cost of our scheme becomes smaller as the network grows). We analyze our scheme and implement and experiment it on an Open vSwitch-based testbed and on CloudLab to validate these properties.
引用
收藏
页码:308 / 320
页数:13
相关论文
共 16 条
  • [1] Hop-by-hop toward future mobile broadband IP
    Mähönen, P
    Riihijärvi, J
    Petrova, M
    Shelby, Z
    IEEE COMMUNICATIONS MAGAZINE, 2004, 42 (03) : 138 - 146
  • [2] SDAP: A secure Hop-by-hop Data Aggregation Protocol for sensor networks
    Yang, Yi
    Wang, Xinran
    Zhu, Sencun
    Cao, Guohong
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2008, 11 (04)
  • [3] A lightweight hop-by-hop routing authenticated protocol for micro-mobility IP network
    Tie, L
    Wang, YJ
    Li, Z
    Jue, W
    PROCEEDINGS OF THE IEEE 6TH CIRCUITS AND SYSTEMS SYMPOSIUM ON EMERGING TECHNOLOGIES: FRONTIERS OF MOBILE AND WIRELESS COMMUNICATION, VOLS 1 AND 2, 2004, : 129 - 131
  • [4] Authentication of the Message through Hop-by-Hop and Secure the Source Nodes in Wireless Sensor Networks
    Kumar, B. Anil
    Rao, N. Bhaskara
    Sunitha, M. S.
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON FRONTIERS OF INTELLIGENT COMPUTING: THEORY AND APPLICATIONS (FICTA) 2014, VOL 2, 2015, 328 : 785 - 791
  • [5] Fast Datapath Processing Based on Hop-by-Hop Packet Aggregation for Service Function Chaining
    Taguchi, Yuki
    Kawashima, Ryota
    Nakayama, Hiroki
    Hayashi, Tsunemasa
    Matsuo, Hiroshi
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2019, E102D (11): : 2184 - 2194
  • [6] A Local Fast-Reroute mechanism for single node or link protection in hop-by-hop routed networks
    Su, Hui-Kai
    COMPUTER COMMUNICATIONS, 2012, 35 (08) : 970 - 979
  • [7] CIPMAN:: combining Cellular IP and mobile ad hoc networks in a hop by hop all radio access network
    Abdennebi, M
    Langar, R
    Tohmé, S
    2005 13th IEEE International Conference on Networks Jointly held with the 2005 7th IEEE Malaysia International Conference on Communications, Proceedings 1 and 2, 2005, : 1029 - 1034
  • [8] Fast Address Hopping at the Switches: Securing Access for Packet Forwarding in SDN
    Chang, Sang-Yoon
    Park, Younghee
    Muralidharan, Akshaya
    NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 454 - 460
  • [9] Base station gateway to secure user channel access at the first hop edge
    Chang, Sang-Yoon
    Sarker, Arijet
    Wuthier, Simeon
    Kim, Jinoh
    Kim, Jonghyun
    Zhou, Xiaobo
    COMPUTER NETWORKS, 2024, 240
  • [10] Fast and Slow Hopping MAC Protocol for Single-hop Ad Hoc Wireless Networks
    Almotairi, Khaled Hatem
    Shen, Xuemin
    2011 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2011,