Misreporting Attacks in Software-Defined Networking

被引:2
|
作者
Burke, Quinn [1 ]
McDaniel, Patrick [1 ]
La Porta, Thomas [1 ]
Yu, Mingli [1 ]
He, Ting [1 ]
机构
[1] Penn State Univ, State Coll, PA 16801 USA
基金
美国国家科学基金会;
关键词
Network security; SDN; Load balancing;
D O I
10.1007/978-3-030-63086-7_16
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Load balancers enable efficient use of network resources by distributing traffic fairly across them. In software-defined networking (SDN), load balancing is most often realized by a controller application that solicits traffic load reports from network switches and enforces load balancing decisions through flow rules. This separation between the control and data planes in SDNs creates an opportunity for an adversary at a compromised switch to misreport traffic loads to influence load balancing. In this paper, we evaluate the ability of such an adversary to control the volume of traffic flowing through a compromised switch by misreporting traffic loads. We use a queuing theoretic approach to model the attack and develop algorithms for misreporting that allow an adversary to tune attack parameters toward specific adversarial goals. We validate the algorithms with a virtual network testbed, finding that through misreporting the adversary can draw nearly all of the load in the subnetwork (+750%, or 85% of the load in the system), or an adversary-desired amount of load (a target load, e.g., +200%) to within 12% error of that target. This is yet another example of how depending on untrustworthy reporting in making control decisions can lead to fundamental security failures.
引用
收藏
页码:276 / 296
页数:21
相关论文
共 50 条
  • [41] DDoS protection with stateful software-defined networking
    Rebecchi, Filippo
    Boite, Julien
    Nardin, Pierre-Alexis
    Bouet, Mathieu
    Conan, Vania
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2019, 29 (01)
  • [42] Review on Software-Defined Networking: Architectures and Threats
    Bhatia, Sanchita
    Nathani, Kanak
    Sharma, Vishal
    INFORMATION SYSTEMS DESIGN AND INTELLIGENT APPLICATIONS, INDIA 2017, 2018, 672 : 1003 - 1011
  • [43] Video over Software-Defined Networking (VSDN)
    Owens, Harold, II
    Durresi, Arjan
    COMPUTER NETWORKS, 2015, 92 : 341 - 356
  • [44] Fault Management in Software-Defined Networking: A Survey
    Yu, Yinbo
    Li, Xing
    Leng, Xue
    Song, Libin
    Bu, Kai
    Chen, Yan
    Yang, Jianfeng
    Zhang, Liang
    Cheng, Kang
    Xiao, Xin
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2019, 21 (01): : 349 - 392
  • [45] Intelligent Threat Hunting in Software-Defined Networking
    Schmitt, Steven
    Kandah, Farah I.
    Brownell, Dylan
    2019 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2019,
  • [46] Achieving Dependability in Software-Defined Networking - A Perspective
    Heegaard, Poul E.
    Helvik, Bjarne E.
    Mendiratta, Veena B.
    2015 7TH INTERNATIONAL WORKSHOP ON RELIABLE NETWORKS DESIGN AND MODELING (RNDM) PROCE4EDINGS, 2015, : 63 - 70
  • [47] Testing the Functionality of Firewall in Software-Defined Networking
    Adedayo, Adebayo Oluwaseun
    Twala, Bhekisipho
    ARTIFICIAL INTELLIGENCE AND EVOLUTIONARY COMPUTATIONS IN ENGINEERING SYSTEMS, ICAIECES 2017, 2018, 668 : 1 - 14
  • [48] NDNFlow: Software-Defined Named Data Networking
    van Adrichem, Niels L. M.
    Kuipers, Fernando A.
    2015 1st IEEE Conference on Network Softwarization (NetSoft), 2015,
  • [49] SDNaaS: Software-Defined Networking as an IXP Service
    Mendoza, John Robert
    Frias, Levin
    Austria, Isabel
    Festin, Cedric
    Ocampo, Roel
    2022 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (IEEE NFV-SDN), 2022, : 59 - 65
  • [50] Proactive Host Mutation in Software-Defined Networking
    Aust, Matthew
    Mullins, Barry
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2017), 2017, : 453 - 460