An Extendable Software Architecture for Mitigating ARP Spoofing-Based Attacks in SDN Data Plane Layer

被引:6
|
作者
Buzura, Sorin [1 ]
Lehene, Mihaiela [1 ]
Iancu, Bogdan [1 ]
Dadarlat, Vasile [1 ]
机构
[1] Tech Univ Cluj Napoca, Dept Comp Sci, 28 Memorandumului St, Cluj Napoca 400114, Romania
关键词
ARP spoofing; attack detection; attack mitigation; network security; software architecture; software-defined networking; DEFINED NETWORKING;
D O I
10.3390/electronics11131965
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) is an emerging network architecture that brings benefits in network function virtualization, performance, and scalability. However, the scalability feature also increases the number of possible vulnerabilities through multiple entry points in the network. Address Resolution Protocol (ARP) spoofing-based attacks are widely encountered and allow an attacker to assume the identity of a different computer, facilitating other attacks, such as Man in the Middle (MitM). In the SDN context, most solutions employ a controller to detect and mitigate attacks. However, interacting with the control plane involves asynchronous network communication, which causes delayed responses to an attack. The current work avoids these delays by being implemented solely in the data plane through extendable and customizable software architecture. Therefore, faster response times improve network reliability by automatically blocking attackers. As attacks can be generated with a variety of tools and in networks experiencing different traffic patterns, the current solution is created to allow flexibility and extensibility, which can be adapted depending on the running environment. Experiments were run performing ARP spoofing-based attacks using KaliLinux, Mininet, and OpenVSwitch. The presented results are based on traffic pattern analysis offering greater customization capabilities and insight compared to similar work in this area.
引用
收藏
页数:25
相关论文
共 18 条
  • [1] Mitigating SYN flooding Attack and ARP Spoofing in SDN Data Plane
    Lin, Ting-Yu
    Wu, Then-Ping
    Hung, Pei-Hsuan
    Shao, Ching-Hsuan
    Wang, Yu-Ting
    Cai, Yun-Than
    Tsai, Meng-Hsun
    APNOMS 2020: 2020 21ST ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2020, : 114 - 119
  • [2] LSAV: Lightweight source address validation in SDN to counteract IP spoofing-based DDoS attacks
    Karakoc, Ali
    Alagoz, Fatih
    TURKISH JOURNAL OF ELECTRICAL ENGINEERING AND COMPUTER SCIENCES, 2023, 31 (07) : 1187 - 1205
  • [3] Detecting and Mitigating ARP Attacks in SDN-Based Cloud Environment
    Sun, Sixian
    Fu, Xiao
    Luo, Bin
    Du, Xiaojiang
    IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 659 - 664
  • [4] Towards a SDN-Based Integrated Architecture for Mitigating IP Spoofing Attack
    Zhang, Chaoqin
    Hu, Guangwu
    Chen, Guolong
    Sangaiah, Arun Kumar
    Zhang, Ping'an
    Yan, Xia
    Jiang, Weijin
    IEEE ACCESS, 2018, 6 : 22764 - 22777
  • [5] Deception-based IDS against ARP Spoofing Attacks in Software-Defined Networks
    Mvah, Fabrice
    Tchendji, Vianney Kengne
    Djamegni, Clementin Tayou
    Anwar, Ahmed H.
    Tosh, Deepak K.
    Kamhoua, Charles
    2024 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2024, : 188 - 192
  • [6] Mitigating DDoS Attacks in SDN-Based IoT Networks Leveraging Secure Control and Data Plane Algorithm
    Wang, Song
    Gomez, Karina
    Sithamparanathan, Kandeepan
    Asghar, Muhammad Rizwan
    Russello, Giovanni
    Zanna, Paul
    APPLIED SCIENCES-BASEL, 2021, 11 (03): : 1 - 27
  • [7] E2BaSeP: Efficient Bayes Based Security Protocol Against ARP Spoofing Attacks in SDN Architectures
    Vianney Kengne Tchendji
    Fabrice Mvah
    Clémentin Tayou Djamegni
    Yannick Florian Yankam
    Journal of Hardware and Systems Security, 2021, 5 (1) : 58 - 74
  • [8] Detecting and Mitigating Denial of Service Attacks against the Data Plane in Software Defined Networks
    Durner, Raphael
    Lorenz, Claas
    Wiedemann, Michael
    Kellerer, Wolfgang
    2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [9] GaTeBaSep: game theory-based security protocol against ARP spoofing attacks in software-defined networks
    Mvah, Fabrice
    Tchendji, Vianney Kengne
    Djamegni, Clementin Tayou
    Anwar, Ahmed H.
    Tosh, Deepak K.
    Kamhoua, Charles
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (01) : 373 - 387
  • [10] GaTeBaSep: game theory-based security protocol against ARP spoofing attacks in software-defined networks
    Fabrice Mvah
    Vianney Kengne Tchendji
    Clémentin Tayou Djamegni
    Ahmed H. Anwar
    Deepak K. Tosh
    Charles Kamhoua
    International Journal of Information Security, 2024, 23 : 373 - 387