Behavior Anomaly Detection in SDN Control Plane:A Case Study of Topology Discovery Attacks

被引:0
|
作者
Chou, Li-Der [1 ]
Liu, Chien-Chang [1 ]
Lai, Meng-Sheng [1 ]
Chiu, Kai-Cheng [1 ]
Tu, Hsuan-Hao [1 ]
Su, Sen [2 ]
Lai, Chun-Lin [2 ]
Yen, Chia-Kuan [2 ]
Tsai, Wei-Hsiang [2 ]
机构
[1] Natl Cent Univ, Dept Comp Sci & Informat Engn, Taoyuan, Taiwan
[2] Natl Chung Shan Inst Sci & Technol, Informat & Commun Res Div, Taoyuan, Taiwan
关键词
Software Defined Networking; topology discovery attacks; OpenFlow Discovery Protocol; Link Layer Discovery Protocol;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The SDN controller uses the OpenFlow Discovery Protocol (OFDP) to collect network topology status. OFDP detects the link between OpenFlow switches by generating Link Layer Discovery Protocol (LLDP) packets. However, OFDP is not a completely secure protocol and can be used by attackers to perform topology discovery injection attacks, topology discovery man-in-the-middle attacks, and topology discovery flood attacks, thereby confusing the network topology. This paper proposes a Correlation-based Topology Anomaly Detection (CTAD) mechanism to run in a software-defined network controller. Spearman's rank correlation is used to analyze the correlation between network traffic between links and measure the time difference between the round trip time of each LLDP frame to determine whether the topology man-in-the-middle attack exists in the network. This paper also adds a dynamic authentication key and counting mechanism in the LLDP frame to prevent attackers from using the topology discovery injection attack to generate fake links and topology discovery flooding attacks, causing network routing or switching abnormalities.
引用
收藏
页码:357 / 362
页数:6
相关论文
共 50 条
  • [31] ieHDDP: An Integrated Solution for Topology Discovery and Automatic In-Band Control Channel Establishment for Hybrid SDN Environments
    Alvarez-Horcajo, Joaquin
    Martinez-Yelmo, Isaias
    Rojas, Elisa
    Antonio Carral, Juan
    Carrascal, David
    SYMMETRY-BASEL, 2022, 14 (04):
  • [32] Automatic Control Network Anomaly Detection Based on Behavior Understanding
    Luo, Jianhui
    2021 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, ICWS 2021, 2021, : 645 - 647
  • [33] Case Study of Anomaly Detection and Quality Control of Energy Efficiency and Hygrothermal Comfort in Buildings
    Eiras-Franco, Carlos
    Flores, Miguel
    Bolon-Canedo, Veronica
    Zaragoza, Sonia
    Fernandez-Casal, Ruben
    Naya, Salvador
    Tarrio-Saavedra, Javier
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON DATA SCIENCE, TECHNOLOGY AND APPLICATIONS (DATA), 2019, : 145 - 151
  • [34] Response Time and Availability Study of RAFT Consensus in Distributed SDN Control Plane
    Sakic, Ermin
    Kellerer, Wolfgang
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2018, 15 (01): : 304 - 318
  • [35] Implementation of Anomaly Detection Algorithms for Detecting Transmission Control Protocol Synchronized Flooding Attacks
    Mkuzangwe, Nenekazi N. P.
    McDonald, Andre
    Nelwamondo, Fulufhelo V.
    2015 12th International Conference on Fuzzy Systems and Knowledge Discovery (FSKD), 2015, : 2137 - 2141
  • [36] Anomaly Detection using Machine Learning with a Case Study
    Jidiga, Goverdhan Reddy
    Sammulal, P.
    2014 INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION CONTROL AND COMPUTING TECHNOLOGIES (ICACCCT), 2014, : 1060 - 1065
  • [37] Detection of Network Buffer Overflow Attacks: A Case Study
    Maros, Barabas
    Ivan, Homoliak
    Matej, Kacic
    Petr, Hanacek
    2013 47TH INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2013,
  • [38] Automatic detection of attacks on cryptographic protocols: A case study
    Cibrario, I
    Durante, L
    Sisto, R
    Valenzano, A
    DETECTION OF INTRUSIONS AND MALWARE, AND VULNERABILITY ASSESSMENT, PROCEEDINGS, 2005, 3548 : 69 - 84
  • [39] Progressively Adding Objectives: A Case Study in Anomaly Detection
    Marti, Luis
    Fansi-Tchango, Arsene
    Navarro, Laurent
    Schoenauer, Marc
    PROCEEDINGS OF THE 2017 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE (GECCO'17), 2017, : 593 - 600
  • [40] Generating IoT traffic: A Case Study on Anomaly Detection
    Nguyen-An, Hung
    Silverston, Thomas
    Yamazaki, Taku
    Miyoshi, Takumi
    2020 26TH IEEE INTERNATIONAL SYMPOSIUM ON LOCAL AND METROPOLITAN AREA NETWORKS (IEEE LANMAN), 2020,