Mitigating ARP Cache Poisoning Attack in Software-Defined Networking (SDN): A Survey

被引:15
|
作者
Shah, Zawar [1 ,2 ]
Cosgrove, Steve [3 ]
机构
[1] Whitireia Community Polytech, Sch Informat Technol, Auckland 1010, New Zealand
[2] Australian Inst Higher Educ, Dept Business Informat Syst, Sydney, NSW 2000, Australia
[3] Whitireia Community Polytech, Sch Informat Technol, Wellington 5022, New Zealand
关键词
ARP cache poisoning attack; Software-Defined Networking (SDN); Denial of Service (DoS) attack; Man in the Middle (MITM) attack; FUTURE;
D O I
10.3390/electronics8101095
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Address Resolution Protocol (ARP) is a widely used protocol that provides a mapping of Internet Protocol (IP) addresses to Media Access Control (MAC) addresses in local area networks. This protocol suffers from many spoofing attacks because of its stateless nature and lack of authentication. One such spoofing attack is the ARP Cache Poisoning attack, in which attackers poison the cache of hosts on the network by sending spoofed ARP requests and replies. Detection and mitigation of ARP Cache Poisoning attack is important as this attack can be used by attackers to further launch Denial of Service (DoS) and Man-In-The Middle (MITM) attacks. As with traditional networks, an ARP Cache Poisoning attack is also a serious concern in Software Defined Networking (SDN) and consequently, many solutions are proposed in the literature to mitigate this attack. In this paper, a detailed survey on various solutions to mitigate ARP Cache Poisoning attack in SDN is carried out. In this survey, various solutions are classified into three categories: Flow Graph based solutions; Traffic Patterns based solutions; IP-MAC Address Bindings based solutions. All these solutions are critically evaluated in terms of their working principles, advantages and shortcomings. Another important feature of this survey is to compare various solutions with respect to different performance metrics, e.g., attack detection time, ARP response time, calculation of delay at the Controller etc. In addition, future research directions are also presented in this survey that can be explored by other researchers to propose better solutions to mitigate the ARP Cache Poisoning attack in SDN.
引用
收藏
页数:26
相关论文
共 50 条
  • [1] Software-defined networking (SDN): a survey
    Benzekki, Kamal
    El Fergougui, Abdeslam
    Elalaoui, Abdelbaki Elbelrhiti
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) : 5803 - 5833
  • [2] Mitigating the Table-Overflow Attack in Software-Defined Networking
    Xu, Tong
    Gao, Deyun
    Dong, Ping
    Foh, Chuan Heng
    Zhang, Hongke
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (04): : 1086 - 1097
  • [3] State-of-the-art survey on software-defined networking (SDN)
    Zhang, Chao-Kun
    Cui, Yong
    Tang, He-Yi
    Wu, Jian-Ping
    [J]. Ruan Jian Xue Bao/Journal of Software, 2015, 26 (01): : 62 - 81
  • [4] ON PREVENTING ARP POISONING ATTACK UTILIZING SOFTWARE DEFINED NETWORK (SDN) PARADIGM
    Masoud, Mohammad Z.
    Jaradat, Yousf
    Jannoud, Ismael
    [J]. 2015 IEEE JORDAN CONFERENCE ON APPLIED ELECTRICAL ENGINEERING AND COMPUTING TECHNOLOGIES (AEECT), 2015,
  • [5] Mitigating TCP Incast Issue in Cloud Data Centres using Software-Defined Networking (SDN): A Survey
    Shah, Zawar
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2018, 12 (11): : 5179 - 5202
  • [6] ARP Poisoning attack Detection based on ARP Update state in Software-Defined Networks.
    Kim, Youngpin
    Ahn, Sungwon
    Nguyen Canh Thang
    Choi, Dongho
    Park, Minho
    [J]. 33RD INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2019), 2019, : 366 - 371
  • [7] A Survey on Software-Defined Networking
    Xia, Wenfeng
    Wen, Yonggang
    Foh, Chuan Heng
    Niyato, Dusit
    Xie, Haiyong
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (01): : 27 - 51
  • [8] Status of address spoofing attack prevention techniques in software-defined networking (SDN)
    Meena, Ramesh Chand
    Meena, Keshav
    Kumar, Ankit
    Gupta, Mukesh
    Kumar, Santosh
    [J]. JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2021, 24 (08): : 2341 - 2351
  • [9] Software-Defined Networking: A survey
    Farhady, Hamid
    Lee, HyunYong
    Nakao, Akihiro
    [J]. COMPUTER NETWORKS, 2015, 81 : 79 - 95
  • [10] On Software-defined networking and the design of SDN Controllers
    Hoang, Doan B.
    Minh Pham
    [J]. 2015 6TH INTERNATIONAL CONFERENCE ON THE NETWORK OF THE FUTURE (NOF), 2015,