Game-Theoretic Framework for Malicious Controller Detection in Software Defined Networks

被引:2
|
作者
Sridharan, Vignesh [1 ]
Gurusamy, Mohan [2 ]
机构
[1] Natl Univ Singapore, Singapore, Singapore
[2] Natl Univ Singapore, Fac Engn, Singapore, Singapore
关键词
Control systems; Switches; Security; Optimization; Games; Heuristic algorithms; Time factors; Game theory; malicious controller; SDN; Stackelberg game; switch-controller mapping;
D O I
10.1109/TNSM.2021.3051064
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The separation of control and data plane in Software Defined Networking (SDN) introduces new security threats. A compromised controller can leverage its position to perform attacks by installing malicious rules in switches while avoiding detection. Current approaches propose broadcast of flow-setup requests to multiple controllers simultaneously and to check consistency of forwarding rules to install the correct rule and identify compromised controllers. However, such approaches result in heavy load on the control plane, resulting in longer response times to requests and higher network cost to accommodate the increased load. To alleviate this issue, we propose a game-theory based framework to detect a malicious controller without overloading the control plane. Instead of broadcasting every request to multiple controllers, switches randomly broadcast requests on the basis of a randomization strategy obtained by the Stackelberg game, whose solution results in a randomization strategy that maximizes the detection probability of a malicious controller. We formulate a two-level optimization problem in the context of our game-theoretic framework that aims to maximize the attack detection probability among the set of controllers by mapping switches to controllers and obtaining randomization strategies for each controller. We develop Midas (MalIcious controller Detection mApping Strategy), a heuristic algorithm to obtain an effective solution to the optimization problem in reasonable time. Midas achieves minimum detection probability within 12% of the optimal solution. Further, it achieves at least 80% of min-max ratio of load at the controllers, implying higher fairness in load distribution compared to optimal solution, a state-of-art algorithm and a baseline heuristic.
引用
收藏
页码:3107 / 3120
页数:14
相关论文
共 50 条
  • [1] Game-Theoretic Approach to Malicious Controller Detection in Software Defined Networks
    Sridharan, Vignesh
    Gurusamy, Mohan
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2018,
  • [2] Game-Theoretic Approach to Attack Planning and Controller Placement in Software Defined Networks
    Junosza-Szaniawski, Konstanty
    Nogalski, Dariusz
    [J]. 2023 INTERNATIONAL CONFERENCE ON MILITARY COMMUNICATIONS AND INFORMATION SYSTEMS, ICMCIS, 2023,
  • [3] Community detection in networks: a game-theoretic framework
    Chen, Yan
    Cao, Xuanyu
    Liu, K. J. Ray
    [J]. EURASIP JOURNAL ON ADVANCES IN SIGNAL PROCESSING, 2019, 2019 (01)
  • [4] Community detection in networks: a game-theoretic framework
    Yan Chen
    Xuanyu Cao
    K. J. Ray Liu
    [J]. EURASIP Journal on Advances in Signal Processing, 2019
  • [5] Game-Theoretic Switching Detection of Malicious Attacks in Switched Systems
    Huang, Yabing
    Zhao, Jun
    [J]. IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2023, 10 (02): : 951 - 965
  • [6] A Bayesian Game-Theoretic Intrusion Detection System for Hypervisor-Based Software Defined Networks in Smart Grids
    Niazi, Rumaisa Aimen
    Faheem, Yasir
    [J]. IEEE ACCESS, 2019, 7 : 88656 - 88672
  • [7] The Price of Malice: A Game-Theoretic Framework for Malicious Behavior in Distributed Systems
    Moscibroda, Thomas
    Schmid, Stefan
    Wattenhofer, Roger
    [J]. INTERNET MATHEMATICS, 2009, 6 (02) : 125 - 155
  • [8] Game Theoretic Switch-controller Mapping with Traffic Variations in Software Defined Networks
    Mohanasundaram, Jayendhar Gautham
    Tram Truong-Huu
    Gurusamy, Mohan
    [J]. 2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [9] Countering ARP spoofing attacks in software-defined networks using a game-theoretic approach
    Mvah, Fabrice
    Tchendji, Vianney Kengne
    Djamegni, Clementin Tayou
    Anwar, Ahmed H.
    Tosh, Deepak K.
    Kamhoua, Charles
    [J]. COMPUTERS & SECURITY, 2024, 139
  • [10] A Game-Theoretic Framework for Robust Optimal Intrusion Detection in Wireless Sensor Networks
    Moosavi, Hussein
    Bui, Francis Minhthang
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2014, 9 (09) : 1367 - 1379