DDoS attacks on data plane of software-defined network: are they possible?

被引:7
|
作者
Wu, Xiaotong [1 ]
Liu, Meng [1 ]
Dou, Wanchun [1 ]
Yu, Shui [2 ]
机构
[1] Nanjing Univ, State Key Lab Novel Software Technol, Nanjing, Jiangsu, Peoples R China
[2] Deakin Univ, Sch Informat Technol, Burwood, Vic 3125, Australia
基金
美国国家科学基金会;
关键词
software-defined network; flooding DDoS; stealthy DDoS; DDoS detection; SECURITY;
D O I
10.1002/sec.1709
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With software-defined networking (SDN) becoming the leading technology for large-scale networks, it is definitely expected that SDN will suffer various types of distributed denial-of-service (DDoS) attacks because of its centralized control logic. However, almost all of existing works concentrate on the controller overloading DDoS attacks, while vulnerabilities exposed by data plane of SDN for DDoS attacks are largely ignored. In this paper, we firstly investigate a flow rule flooding DDoS attack. By thoroughly analyzing the flow table size and miss rate, we find that attackers are able to inflict significant performance degradation over the system with limited volume of attack resource. We then prove that it is possible for attackers to maximize the performance degradation and minimize the attack rate at the same time. Besides the flooding DDoS attack, we also study a novel DDoS attack targeting data plane of SDN. By utilizing the entry lifetime management mechanism of flow tables, this attack almost never exhibits an intensive controller access behavior. It flies under the radar by inflicting non-notable performance impact on the system, while it creates heavy long-term financial burden on the target application. Finally, we present a potential countermeasure for this stealthy DDoS attack. Through extensive experiments, we conclude that DDoS attacks targeting data plane are possible. Copyright (C) 2016 John Wiley & Sons, Ltd.
引用
收藏
页码:5444 / 5459
页数:16
相关论文
共 50 条
  • [1] On the Impact of DDoS Attacks on Software-Defined Internet-of-Vehicles Control Plane
    Siddiqui, Abdul Jabbar
    Boukerche, Azzedine
    2018 14TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2018, : 1284 - 1289
  • [2] Addressing Spoofed DDoS Attacks in Software-defined Networking
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    2021 6TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2021,
  • [3] Distributed Denial of Service (DDoS) Attacks in Software-defined Networks (SDN)
    Chahal, Jasmeen Kaur
    Kaur, Puninder
    Sharma, Avinash
    2021 5TH INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, COMMUNICATION, COMPUTER TECHNOLOGIES AND OPTIMIZATION TECHNIQUES (ICEECCOT), 2021, : 291 - 295
  • [4] Automated Controller Placement for Software-Defined Networks to Resist DDoS Attacks
    Haque, Muhammad Reazul
    Tan, Saw Chin
    Yusoff, Zulfadzli
    Nisar, Kashif
    Kwang, Lee Ching
    Kaspin, Rizaludin
    Chowdhry, Bhawani Shankar
    Buyya, Rajkumar
    Majumder, Satya Prasad
    Gupta, Manoj
    Memon, Shuaib
    CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 68 (03): : 3147 - 3165
  • [5] In-Network Data Processing in Software-Defined IoT with a Programmable Data Plane
    Kim, Ki-Wook
    Min, Sung-Gi
    Han, Youn-Hee
    MOBILE INFORMATION SYSTEMS, 2018, 2018
  • [6] SGS: Safe-Guard Scheme for Protecting Control Plane Against DDoS Attacks in Software-Defined Networking
    Wang, Yang
    Hu, Tao
    Tang, Guangming
    Xie, Jichao
    Lu, Jie
    IEEE ACCESS, 2019, 7 : 34699 - 34710
  • [7] An Energy-Efficient Topology Design and DDoS Attacks Mitigation for Green Software-Defined Satellite Network
    Tu, Zhe
    Zhou, Huachun
    Li, Kun
    Li, Man
    Tian, Aleteng
    IEEE ACCESS, 2020, 8 : 211434 - 211450
  • [8] Detection and Mitigation of DDoS Attacks Using Conditional Entropy in Software-defined Networking
    Xuanyuan, Ming
    Ramsurrun, Visham
    Seeam, Amar
    2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 66 - 71
  • [9] Control Plane Reflection Attacks and Defenses in Software-Defined Networks
    Zhang, Menghao
    Li, Guanyu
    Xu, Lei
    Bai, Jiasong
    Xu, Mingwei
    Gu, Guofei
    Wu, Jianping
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2021, 29 (02) : 623 - 636
  • [10] Effective software-defined networking controller scheduling method to mitigate DDoS attacks
    Yan, Q.
    Gong, Q.
    Yu, F. R.
    ELECTRONICS LETTERS, 2017, 53 (07) : 469 - 471