Towards a SDN-Based Integrated Architecture for Mitigating IP Spoofing Attack

被引:19
|
作者
Zhang, Chaoqin [1 ,2 ]
Hu, Guangwu [3 ]
Chen, Guolong [4 ]
Sangaiah, Arun Kumar [5 ]
Zhang, Ping'an [3 ]
Yan, Xia [3 ]
Jiang, Weijin [6 ]
机构
[1] Natl Digital Switches Syst Engn & Technol Researc, Zhengzhou 450002, Henan, Peoples R China
[2] Zhengzhou Univ Light Ind, Sch Comp & Commun Engn, Zhengzhou 450001, Henan, Peoples R China
[3] Shenzhen Inst Informat Technol, Sch Comp Sci, Shenzhen 518172, Peoples R China
[4] Huawei Technol, Shenzhen 518055, Peoples R China
[5] VIT Univ, Sch Comp Sci & Engn, Vellore 632014, Tamil Nadu, India
[6] Hunan Univ Commerce, Coll Comp & Informat Engn, Changsha 410205, Hunan, Peoples R China
来源
IEEE ACCESS | 2018年 / 6卷
基金
中国国家自然科学基金;
关键词
Cyber-security; IP address validation; software-defined networking; INTERNET;
D O I
10.1109/ACCESS.2017.2785236
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Current Internet packet delivery only relies on packet's destination IP address and forwarding devices neglect the validation of packet's IP source address, it makes attackers can leverage this flaw to launch attacks with forged IP source address so as to meet their vicious purposes and avoid to be tracked. In order to mitigate this threat and enhance Internet accountability, many solutions have been proposed either from the intra-domain or the inter-domain aspects. However, most of them faced with some issues hard to cope with, e.g., low filtering rates, high deployment cost. And most importantly, few of them can cover both intra-domain and inter-domain areas at the same time. With the central control and edge response pattern, the novel network architecture of software defined networking (SDN) possess whole network intelligence and distribute control rules directly to edged SDN switches, which brings a good opportunity to solve the IP spoofing problem. By taking advantage of SDN, in this paper, we propose an SDN-based integrated IP source address validation architecture (ISAVA) which can cover both intra- and inter-domain areas and effectively lower SDN devices deployment cost, while achieve desirable control granularities in the meantime. Specifically, within autonomous system (AS), ISAVA relies on an SDN incremental deployment scheme which can achieve IP prefix (subnet)-level validation granularity with minimum SDN devices deployment. While among ASes, ISAVA sets up border server and establishes a vouch mechanism between allied ASes for signing outbound packets so as to achieve AS-level validation granularity. Finally, conducted experiments confirm that ISAVA intra-domain scheme can get beyond 90% filtering rates with only 10% deployment in average, while the inter-domain scheme can get high filtering rates with low system cost and less storage usage.
引用
收藏
页码:22764 / 22777
页数:14
相关论文
共 50 条
  • [41] Control Channel Denial-of-Service Attack in SDN-Based Networks
    Sriskandarajah, Shriparen
    McKague, Matthew
    Foo, Ernest
    Ragel, Roshan G.
    Karunarathna, Suneth Namal
    Jadidi, Zahra
    [J]. MERCON 2020: 6TH INTERNATIONAL MULTIDISCIPLINARY MORATUWA ENGINEERING RESEARCH CONFERENCE (MERCON), 2020, : 325 - 330
  • [42] XGBoost Classifier for DDoS Attack Detection and Analysis in SDN-based Cloud
    Chen, Zhuo
    Jiang, Fu
    Cheng, Yijun
    Gu, Xin
    Liu, Weirong
    Peng, Jun
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA AND SMART COMPUTING (BIGCOMP), 2018, : 251 - 256
  • [43] Seamless Multicast : an SDN-based architecture for continuous audiovisual transport
    Colombo, Constant
    Lepage, Francis
    Kopp, Rene
    Gnaedinger, Eric
    [J]. TELECOMMUNICATION SYSTEMS, 2021, 78 (02) : 187 - 202
  • [44] An SDN-Based Dynamic Security Architecture for Space Information Networks
    Wang, Ziqi
    Cui, Baojiang
    Yao, Shen
    Jiang, Meiyi
    [J]. SPACE INFORMATION NETWORKS, SINC 2019, 2020, 1169 : 99 - 111
  • [45] SDN-based gateway architecture for electromagnetic nano-networks
    Galal, Akram
    Hesselbach, Xavier
    Tavernier, Wouter
    Colle, Didier
    [J]. COMPUTER COMMUNICATIONS, 2022, 184 : 160 - 173
  • [46] SDN-based heterogeneous network architecture with Multi-Controllers
    Park, Junhyuk
    Yoon, Wonyong
    [J]. 2020 22ND INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): DIGITAL SECURITY GLOBAL AGENDA FOR SAFE SOCIETY!, 2020, : 559 - 561
  • [47] An SDN-based Network Architecture for Extremely Dense Wireless Networks
    Ali-Ahmad, Hassan
    Cicconetti, Claudio
    de la Oliva, Antonio
    Mancuso, Vincenzo
    Sama, Malla Reddy
    Seite, Pierrick
    Shanmugalingam, Sivasothy
    [J]. 2013 IEEE WORKSHOP ON SOFTWARE DEFINED NETWORKS FOR FUTURE NETWORKS AND SERVICES (SDN4FNS 2013), 2013,
  • [48] TARN: A SDN-based Traffic Analysis Resistant Network Architecture
    Yu, Lu
    Wang, Qing
    Barrineau, Geddings
    Oakley, Jon
    Brooks, Richard R.
    Wang, Kuang-Ching
    [J]. PROCEEDINGS OF THE 2017 12TH INTERNATIONAL CONFERENCE ON MALICIOUS AND UNWANTED SOFTWARE (MALWARE), 2017, : 91 - 98
  • [49] An SDN-based cloud computing architecture and its mathematical model
    Yen, Tseng-Chang
    Su, Chi-Sheng
    [J]. 2014 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE, ELECTRONICS AND ELECTRICAL ENGINEERING (ISEEE), VOLS 1-3, 2014, : 1727 - +
  • [50] SDN-based wireless mobile backhaul architecture: Review and challenges
    Hoang Minh Do
    Gregory, Mark A.
    Li, Shuo
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 189