Towards a SDN-Based Integrated Architecture for Mitigating IP Spoofing Attack

被引:19
|
作者
Zhang, Chaoqin [1 ,2 ]
Hu, Guangwu [3 ]
Chen, Guolong [4 ]
Sangaiah, Arun Kumar [5 ]
Zhang, Ping'an [3 ]
Yan, Xia [3 ]
Jiang, Weijin [6 ]
机构
[1] Natl Digital Switches Syst Engn & Technol Researc, Zhengzhou 450002, Henan, Peoples R China
[2] Zhengzhou Univ Light Ind, Sch Comp & Commun Engn, Zhengzhou 450001, Henan, Peoples R China
[3] Shenzhen Inst Informat Technol, Sch Comp Sci, Shenzhen 518172, Peoples R China
[4] Huawei Technol, Shenzhen 518055, Peoples R China
[5] VIT Univ, Sch Comp Sci & Engn, Vellore 632014, Tamil Nadu, India
[6] Hunan Univ Commerce, Coll Comp & Informat Engn, Changsha 410205, Hunan, Peoples R China
来源
IEEE ACCESS | 2018年 / 6卷
基金
中国国家自然科学基金;
关键词
Cyber-security; IP address validation; software-defined networking; INTERNET;
D O I
10.1109/ACCESS.2017.2785236
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Current Internet packet delivery only relies on packet's destination IP address and forwarding devices neglect the validation of packet's IP source address, it makes attackers can leverage this flaw to launch attacks with forged IP source address so as to meet their vicious purposes and avoid to be tracked. In order to mitigate this threat and enhance Internet accountability, many solutions have been proposed either from the intra-domain or the inter-domain aspects. However, most of them faced with some issues hard to cope with, e.g., low filtering rates, high deployment cost. And most importantly, few of them can cover both intra-domain and inter-domain areas at the same time. With the central control and edge response pattern, the novel network architecture of software defined networking (SDN) possess whole network intelligence and distribute control rules directly to edged SDN switches, which brings a good opportunity to solve the IP spoofing problem. By taking advantage of SDN, in this paper, we propose an SDN-based integrated IP source address validation architecture (ISAVA) which can cover both intra- and inter-domain areas and effectively lower SDN devices deployment cost, while achieve desirable control granularities in the meantime. Specifically, within autonomous system (AS), ISAVA relies on an SDN incremental deployment scheme which can achieve IP prefix (subnet)-level validation granularity with minimum SDN devices deployment. While among ASes, ISAVA sets up border server and establishes a vouch mechanism between allied ASes for signing outbound packets so as to achieve AS-level validation granularity. Finally, conducted experiments confirm that ISAVA intra-domain scheme can get beyond 90% filtering rates with only 10% deployment in average, while the inter-domain scheme can get high filtering rates with low system cost and less storage usage.
引用
收藏
页码:22764 / 22777
页数:14
相关论文
共 50 条
  • [1] An SDN-Based IP Hopping Communication Scheme against Scanning Attack
    Zhao, Zheng
    Liu, Fenlin
    Gong, Daofu
    Chen, Lin
    Xiang, Fei
    Li, Yan
    [J]. 2017 IEEE 9TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN), 2017, : 559 - 564
  • [2] Mitigating SYN flooding Attack and ARP Spoofing in SDN Data Plane
    Lin, Ting-Yu
    Wu, Then-Ping
    Hung, Pei-Hsuan
    Shao, Ching-Hsuan
    Wang, Yu-Ting
    Cai, Yun-Than
    Tsai, Meng-Hsun
    [J]. APNOMS 2020: 2020 21ST ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2020, : 114 - 119
  • [3] New SDN-based Architecture for Integrated Vehicular Cloud Computing Networking
    Li, Baozhu
    Zhao, Xuhui
    Han, Shiyuan
    Chen, Zhenxiang
    [J]. 2018 INTERNATIONAL CONFERENCE ON SELECTED TOPICS IN MOBILE AND WIRELESS NETWORKING (MOWNET), 2018, : 113 - 116
  • [4] A proposal for an SDN-based SIEPON architecture
    Khalili, Hamzeh
    Sallent, Sebastia
    Ramon Piney, Jose
    Rincon, David
    [J]. OPTICS COMMUNICATIONS, 2017, 403 : 9 - 21
  • [5] SDN-Based Secure Architecture for IoT
    Mishra, Shailendra
    [J]. INTERNATIONAL JOURNAL OF KNOWLEDGE AND SYSTEMS SCIENCE, 2020, 11 (04) : 1 - 16
  • [6] Evaluation of an SDN-based Microservice Architecture
    Holscher, Anton
    Asplund, Mikael
    Boeira, Felipe
    [J]. PROCEEDINGS OF THE 2022 IEEE 8TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2022): NETWORK SOFTWARIZATION COMING OF AGE: NEW CHALLENGES AND OPPORTUNITIES, 2022, : 151 - 156
  • [7] SDN-based hybrid honeypot for attack capture
    Wang, He
    Wu, Bin
    [J]. PROCEEDINGS OF 2019 IEEE 3RD INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2019), 2019, : 1602 - 1606
  • [8] Mitigating Elephant Flows in SDN-Based IXP Networks
    Dias Knob, Luis Augusto
    Esteves, Rafael Pereira
    Zambenedetti Granville, Lisandro
    Rockenbach Tarouco, Liane Margarida
    [J]. 2017 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2017, : 1352 - 1359
  • [9] μSDN: An SDN-based Routing Architecture for Wireless Sensor Networks
    da Silva Santos, Leonardo Francisco
    de Mendonca Junior, Francisco Ferreira
    Dias, Kelvin Lopes
    [J]. 2017 VII BRAZILIAN SYMPOSIUM ON COMPUTING SYSTEMS ENGINEERING (SBESC), 2017, : 63 - 70
  • [10] Towards a SDN-based Architecture for Analyzing Network Traffic in Cloud Computing Infrastructures
    Chirivella-Perez, Enrique
    Gutierrez-Aguado, Juan
    Calero, Jose M. Alcaraz
    Claver, Jose M.
    [J]. 2015 23RD INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2015, : 295 - 299