Dynamic Packet Forwarding Verification in SDN

被引:29
|
作者
Li, Qi [1 ,2 ]
Zou, Xiaoyue [1 ,2 ]
Huang, Qun [3 ]
Zheng, Jing [1 ,2 ]
Lee, Patrick P. C. [4 ]
机构
[1] Tsinghua Univ, Grad Sch Shenzhen, Shenzhen 518055, Guangdong, Peoples R China
[2] Tsinghua Univ, Dept Comp Sci, Beijing 100084, Peoples R China
[3] Chinese Acad Sci, Inst Comp Technol, Beijing 100190, Peoples R China
[4] Chinese Univ Hong Kong, Dept Comp Sci & Engn, Hong Kong, Peoples R China
基金
中国国家自然科学基金;
关键词
Control systems; Cryptography; Protocols; IP networks; Software; Prototypes; Delays; Software-defined networking; attacks; forwarding verification;
D O I
10.1109/TDSC.2018.2810880
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Like traditional IP networking, the emerging Software-Defined Networking (SDN) technology is vulnerable to sophisticated attacks against packets and their forwarding behaviors. However, existing proposals of packet forwarding verification for IP networking cannot be directly applied to the current SDN deployment due to the limited functionalities and resources in commercial off-the-shelf (COTS) SDN switches. We propose DynaPFV, a dynamic packet forwarding verification mechanism that is capable of detecting various sophisticated attacks against packet forwarding. DynaPFV leverages the controllability of SDN to examine both packets and flow statistics across a network of switches to detect violation of packet integrity and forwarding behaviors. To mitigate the verification overhead, DynaPFV dynamically adjusts the rates of packet sampling and flow statistics collection based on the prior detection results in order to preserve the verification accuracy. Furthermore, DynaPFV makes changes to the SDN controller only, and is directly deployable atop COTS SDN switches without modifications. We conduct theoretical analysis on the trade-off between performance and accuracy in our dynamic verification approach. We further prototype DynaPFV using the open-source Floodlight controller, and evaluate our DynaPFV prototype using Mininet simulations and hardware testbed experiments. DynaPFV achieves over 97 percent of verification accuracy only with less than 5 percent of throughput degradation and less than 10 percent of additional forwarding delays.
引用
收藏
页码:915 / 929
页数:15
相关论文
共 50 条
  • [1] LPV: Lightweight Packet Forwarding Verification in SDN
    Wang S.-Y.
    Li Q.
    Zhang Y.
    Jisuanji Xuebao/Chinese Journal of Computers, 2019, 42 (01): : 176 - 189
  • [2] A lightweight packet forwarding verification in SDN using sketch
    Chang, Heyu
    Zhang, Xiaobing
    Si, Nianwen
    Wu, Ping
    COMPUTERS & SECURITY, 2024, 144
  • [3] Port address overloading based packet forwarding verification in SDN
    Wu P.
    Chang C.
    Ma Y.
    Tongxin Xuebao/Journal on Communications, 2021, 42 (07): : 70 - 83
  • [4] Address overloading-based packet forwarding verification in SDN
    Wu P.
    Chang C.
    Zuo Z.
    Ma Y.
    Tongxin Xuebao/Journal on Communications, 2022, 43 (03): : 88 - 100
  • [5] Constant-Size Credential-Based Packet Forwarding Verification in SDN
    Wu, Ping
    Chang, Chao-Wen
    Ma, Ying-Ying
    Zuo, Zhi-Bin
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [6] Packet forwarding with source verification
    Shue, Craig A.
    Gupta, Minaxi
    Davy, Matthew P.
    COMPUTER NETWORKS, 2008, 52 (08) : 1567 - 1582
  • [7] GwPFV: A novel packet forwarding verification mechanism based on gateways in SDN-based storage environment
    Yuming, Liu
    Yong, Wang
    Hao, Feng
    Zeyu, Wang
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 71
  • [8] Fast Address Hopping at the Switches: Securing Access for Packet Forwarding in SDN
    Chang, Sang-Yoon
    Park, Younghee
    Muralidharan, Akshaya
    NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 454 - 460
  • [9] Dynamic routing protocols for anycast packet forwarding
    Shan, CP
    Karuppiah, EK
    Abdullah, R
    APCC 2003: 9TH ASIA-PACIFIC CONFERENCE ON COMMUNICATION, VOLS 1-3, PROCEEDINGS, 2003, : 66 - 70
  • [10] Predictive Forwarding Rule Caching for Latency Reduction in Dynamic SDN
    Um, Doosik
    Park, Hyung-Seok
    Ryu, Hyunho
    Park, Kyung-Joon
    SENSORS, 2025, 25 (01)