Packet Injection Exploiting Attack and Mitigation in Software-Defined Networks

被引:2
|
作者
Li, Jishuai [1 ]
Qin, Sujuan [1 ]
Tu, Tengfei [1 ]
Zhang, Hua [1 ]
Li, Yongsheng [1 ]
机构
[1] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
来源
APPLIED SCIENCES-BASEL | 2022年 / 12卷 / 03期
关键词
software-defined networking (SDN); OpenFlow; packet injection exploiting attack; false hosts; denial-of-service (DoS); detection; defense; DDOS ATTACKS; SECURITY; DEFENSE;
D O I
10.3390/app12031103
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Software-defined networking (SDN) decouples the control plane and data plane through OpenFlow technology and allows flexible network control. It has been widely applied in different areas and has become a focus of attention in the future network. With SDN's development, its security problem has become a necessary point of research to be solved urgently. In this paper, we propose a novel attack, namely, the packet injection exploiting attack. By maliciously injecting false hosts into SDN network topology, attackers can further use them to launch a denial of service (DoS) attack. The consequences affect the throughput and processing capabilities of the controller, severely consume data plane resources, and ultimately affect the entire network. To prevent the packet-injection exploiting attack, we designed PIEDefender, an efficient, protocol-independent component built on SDN controllers to detect and mitigate attacks effectively. We implement the PIEDefender prototype on the Floodlight controller and assess the effectiveness in the software environment. Experimental results show that PIEDefender achieves a 97.8% injection detection precision and a 97.96% DoS detection precision, incurring an average CPU consumption of 10%. The evaluation demonstrates that the PIEDefender can effectively mitigate the attack against SDN with limited overhead.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] Packet Injection Attack and Its Defense in Software-Defined Networks
    Deng, Shuhua
    Gao, Xing
    Lu, Zebin
    Gao, Xieping
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (03) : 695 - 705
  • [2] Protecting Software-Defined Enterprise Networks from Packet Injection Attacks
    ul Huque, Tanvir
    den Hartog, Frank
    [J]. PROCEEDINGS OF THE IEEE 46TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2021), 2021, : 287 - 292
  • [3] A multi-stage attack mitigation mechanism for software-defined home networks
    [J]. 1600, Institute of Electrical and Electronics Engineers Inc., United States (62):
  • [4] A Multi-stage Attack Mitigation Mechanism for Software-defined Home Networks
    Luo, Shibo
    Wu, Jun
    Li, Jianhua
    Guo, Longhua
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2016, 62 (02) : 200 - 207
  • [5] Link Latency Attack in Software-Defined Networks
    Soltani, Sanaz
    Shojafar, Mohammad
    Mostafaei, Habib
    Pooranian, Zahra
    Tafazolli, Rahim
    [J]. PROCEEDINGS OF THE 2021 17TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM 2021): SMART MANAGEMENT FOR FUTURE NETWORKS AND SERVICES, 2021, : 187 - 193
  • [6] ATTAIN: An Attack Injection Framework for Software-Defined Networking
    Ujcich, Benjamin E.
    Thakore, Uttam
    Sanders, William H.
    [J]. 2017 47TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2017, : 567 - 578
  • [7] HTTP DDoS flooding attack mitigation in software-defined networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE Transactions on Information and Systems, 2021, E104D (09) : 1496 - 1499
  • [8] HTTP DDoS Flooding Attack Mitigation in Software-Defined Networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2021, E104D (09): : 1496 - 1499
  • [9] Collaborative detection and mitigation of DDoS in software-defined networks
    Omer Elsier Tayfour
    Muhammad Nadzir Marsono
    [J]. The Journal of Supercomputing, 2021, 77 : 13166 - 13190
  • [10] DoS vulnerabilities and mitigation strategies in software-defined networks
    Deng, Shuhua
    Gao, Xing
    Lu, Zebin
    Li, Zhengfa
    Gao, Xieping
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 125 : 209 - 219