Cloud-based Deception against Network Reconnaissance Attacks using SDN and NFV

被引:0
|
作者
Aydeger, Abdullah [1 ]
Saputro, Nico [2 ]
Akkaya, Kemal [3 ]
机构
[1] Southern Illinois Univ, Dept Comp Sci, Carbondale, IL 62901 USA
[2] Parahyangan Catholic Univ, Dept Elect Engn, Bandung 40141, Jawa Barat, Indonesia
[3] Florida Int Univ, Dept Elect & Comp Engn, Miami, FL 33174 USA
关键词
DEFENSE;
D O I
10.1109/LCN48667.2020.9314797
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
An attacker's success crucially depends on the reconnaissance phase of Distributed Denial of Service (DDoS) attacks, which is the first step to gather intelligence. Although several solutions have been proposed against network reconnaissance attacks, they fail to address the needs of legitimate users' requests. Thus, we propose a cloud-based deception framework which aims to confuse the attacker with reconnaissance replies while allowing legitimate uses. The deception is based on forwarding the reconnaissance packets to a cloud infrastructure through tunneling and SDN so that the returned IP addresses to the attacker will not be genuine. For handling legitimate requests, we create a reflected virtual topology in the cloud to match any changes in the original physical network to the cloud topology using SDN. Through experimentations on GENI platform, we show that our framework can provide reconnaissance responses with negligible delays to the network clients while also reducing the management costs significantly.
引用
收藏
页码:279 / 285
页数:7
相关论文
共 50 条
  • [1] Empirical Study on Reconnaissance Attacks in SDN-aware Network for Evaluating Cyber Deception
    Do Thi Thu Hien
    Hien Do Hoang
    Van-Hau Pham
    [J]. 2021 RIVF INTERNATIONAL CONFERENCE ON COMPUTING AND COMMUNICATION TECHNOLOGIES (RIVF 2021), 2021, : 295 - 300
  • [2] Defensive deception framework against reconnaissance attacks in the cloud with deep reinforcement learning
    Li, Huanruo
    Guo, Yunfei
    Huo, Shumin
    Hu, Hongchao
    Sun, Penghao
    [J]. SCIENCE CHINA-INFORMATION SCIENCES, 2022, 65 (07)
  • [3] Personalizing the Home Network Experience using Cloud-Based SDN
    Gharakheili, Hassan Habibi
    Bass, Jacob
    Exton, Luke
    Sivaraman, Vijay
    [J]. 2014 IEEE 15TH INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM), 2014,
  • [4] Defensive deception framework against reconnaissance attacks in the cloud with deep reinforcement learning
    Huanruo LI
    Yunfei GUO
    Shumin HUO
    Hongchao HU
    Penghao SUN
    [J]. Science China(Information Sciences), 2022, (07) : 67 - 85
  • [5] Defensive deception framework against reconnaissance attacks in the cloud with deep reinforcement learning
    Huanruo Li
    Yunfei Guo
    Shumin Huo
    Hongchao Hu
    Penghao Sun
    [J]. Science China Information Sciences, 2022, 65
  • [6] A Cloud-based Live Streaming Service for SDN-NFV Enabled Carriers
    Casella, A.
    Lombardo, A.
    Melita, M.
    Micalizzi, S.
    Rametta, C.
    Schembra, G.
    Vassallo, A.
    [J]. PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, DATA AND CLOUD COMPUTING (ICC 2017), 2017,
  • [7] SDN and NFV as Enabler for the Distributed Network Cloud
    Marco Hoffmann
    Michael Jarschel
    Rastin Pries
    Peter Schneider
    Admela Jukan
    Wolfgang Bziuk
    Steffen Gebert
    Thomas Zinner
    Phuoc Tran-Gia
    [J]. Mobile Networks and Applications, 2018, 23 : 521 - 528
  • [8] SDN and NFV as Enabler for the Distributed Network Cloud
    Hoffmann, Marco
    Jarschel, Michael
    Pries, Rastin
    Schneider, Peter
    Jukan, Admela
    Bziuk, Wolfgang
    Gebert, Steffen
    Zinner, Thomas
    Tran-Gia, Phuoc
    [J]. MOBILE NETWORKS & APPLICATIONS, 2018, 23 (03): : 521 - 528
  • [9] Detection and mitigation of deception attacks on cloud-based industrial control systems
    Akbarian, Fatemeh
    Tarneberg, William
    Fitzgerald, Emma
    Kihl, Maria
    [J]. 25TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS (ICIN 2022), 2022, : 106 - 110
  • [10] A Home Cloud-based Home Network Auto-Configuration using SDN
    Lee, Minseok
    Kim, Younggi
    Lee, Younghee
    [J]. 2015 IEEE 12TH INTERNATIONAL CONFERENCE ON NETWORKING, SENSING AND CONTROL (ICNSC), 2015, : 444 - 449