Towards Rule Enforcement Verification for Software Defined Networks

被引:0
|
作者
Zhang, Peng [1 ]
机构
[1] Xi An Jiao Tong Univ, Dept Comp Sci & Technol, Xian, Shaanxi, Peoples R China
基金
中国国家自然科学基金;
关键词
Software defined networks; Rule modification attack; verification; Compressive MAC;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software defined networks (SDNs) reshape the ossified network architectures, by introducing centralized and programmable network control. Despite the huge benefits, SDNs also open doors to what we call rule modification attack, an attack largely overlooked by the community. In such an attack, the adversary can modify rules by exploiting implementation vulnerabilities of switch OSes and control channels. As a result, packets may deviate from their original paths, thereby violating network policies. To defend against rule modification attack, this paper introduces a new security primitive named rule enforcement verification (REV). REV allows a controller to check whether switches have enforced the rules installed by it, using message authentication code (MAC). Since using standard MACs will incur heavy switch-to-controller traffic, this paper proposes a new compressive MAC, which allows switches to compress MACs before reporting to the controller. Experiments show that REV based on compressive MAC can achieve a 97% reduction in switch-to-controller traffic, and a 8x increase in verification throughput.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Verifying Rule Enforcement in Software Defined Networks With REV
    Zhang, Peng
    Wu, Hui
    Zhang, Dan
    Li, Qi
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2020, 28 (02) : 917 - 929
  • [2] Troubleshooting Data Plane With Rule Verification in Software-Defined Networks
    Zhao, Yusu
    Zhang, Pengfei
    Wang, Yongkun
    Jin, Yaohui
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2018, 15 (01): : 232 - 244
  • [3] Towards Rule Consistent Updates in Software-Defined Wireless Sensor Networks
    Huang, Meigen
    Yu, Bin
    [J]. CLOUD COMPUTING AND SECURITY, PT VI, 2018, 11068 : 167 - 176
  • [4] HBD: Towards Efficient Reactive Rule Dispatching in Software-Defined Networks
    Chen, Chang
    Hu, Xiaohe
    Zheng, Kai
    Wang, Xiang
    Xiang, Yang
    Li, Jun
    [J]. TSINGHUA SCIENCE AND TECHNOLOGY, 2016, 21 (02) : 196 - 209
  • [5] HBD: Towards Efficient Reactive Rule Dispatching in Software-Defined Networks
    Chang Chen
    Xiaohe Hu
    Kai Zheng
    Xiang Wang
    Yang Xiang
    Jun Li
    [J]. Tsinghua Science and Technology, 2016, 21 (02) : 196 - 209
  • [6] Towards Automated Verification of Active Cyber Defense Strategies on Software Defined Networks
    Alsaleh, Mohammed Noraden
    Al-Shaer, Ehab
    [J]. PROCEEDINGS OF THE 2016 ACM WORKSHOP ON AUTOMATED DECISION MAKING FOR ACTIVE CYBER DEFENSE (SAFECONFIG'16), 2016, : 23 - 29
  • [7] A characterisation of verification tools for software defined networks
    Lavado L.
    Panizo L.
    Gallardo M.-D.-M.
    Merino P.
    [J]. Journal of Reliable Intelligent Environments, 2017, 3 (3) : 189 - 207
  • [8] Rule Anomalies Detecting and Resolving for Software Defined Networks
    Wang, Pengzhan
    Huang, Liusheng
    Xu, Hongli
    Leng, Bing
    Guo, Hansong
    [J]. 2015 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2015,
  • [9] An Adaptable Rule Placement for Software-Defined Networks
    Zhang, Shuyuan
    Ivancic, Franjo
    Lumezanu, Cristian
    Yuan, Yifei
    Gupta, Aarti
    Malik, Sharad
    [J]. 2014 44TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2014, : 88 - 99
  • [10] A Formal Model and Verification Problems for Software Defined Networks
    Zakharov, V. A.
    Smelyansky, R. L.
    Chemeritsky, E. V.
    [J]. AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2014, 48 (07) : 398 - 406