Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: a comprehensive approach

被引:0
|
作者
Manar Aldaoud
Dawood Al-Abri
Ahmed Al Maashri
Firdous Kausar
机构
[1] Sultan Qaboos University,Department of Electrical and Computer Engineering, College of Engineering
关键词
Software Defined Networking (SDN); OpenFlow; Network Security; Yersinia; DHCP Starvation Attack; DHCP Rouge Server;
D O I
暂无
中图分类号
学科分类号
摘要
Software Defined Networking (SDN) is an approach that provides centralized control and management of networks. This centralized view of the network traffic flow can be exploited to enhance the network's overall security. This paper focuses on protecting SDN networks from DHCP attacks, which not only impact the DHCP service but also extend to the SDN controller and the overall network. This paper proposes a real-time and comprehensive approach—DHCPWatcher—to detect and mitigate DHCP attacks in SDN networks. The DHCPWatcher is a multi-stage detection mechanism for detecting DHCP attacks using anomaly, heuristic, and/or behavior analysis. When an attack is detected, a DROP action for malicious DHCP traffic is injected into the forwarding device using the OpenFlow protocol. Then, a multi-step mechanism is activated to heal and restore the affected controller and the DHCP service that includes removing spoofed hosts from the controller, releasing IP addresses that may have been maliciously leased by the attack, and reassigning those IP addresses to their original clients. Mininet emulator is utilized to evaluate DHCPWatcher against well-known DHCP attacks for three different DHCP services. The results show that DHCPWatcher effectively detects attacks from the first attack packet. It also can neutralize the impacts of most malicious attacks—Yersinia—within the first 30 s and takes much less time for the other attacks, such as Hyena and DHCPwn. This fast neutralization of attacks positively reflects on the controller resources, such as CPU utilization, and network performance in terms of latency and packet loss.
引用
收藏
页码:597 / 614
页数:17
相关论文
共 50 条
  • [1] Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: a comprehensive approach
    Aldaoud, Manar
    Al-Abri, Dawood
    Al Maashri, Ahmed
    Kausar, Firdous
    [J]. JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2023, 19 (04) : 597 - 614
  • [2] An approach for detecting encrypted insider attacks on OpenFlow SDN Networks
    Neu, Charles V.
    Zorzo, Avelino F.
    Orozco, Alex M. S.
    Michelin, Regio A.
    [J]. 2016 11TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2016, : 210 - 215
  • [3] Mitigating DDoS Attacks Using OpenFlow-Based Software Defined Networking
    Jonker, Mattijs
    Sperotto, Anna
    [J]. INTELLIGENT MECHANISMS FOR NETWORK CONFIGURATION AND SECURITY, 2015, 9122 : 129 - 133
  • [4] Implications and Detection of DoS Attacks in OpenFlow-based Networks
    Hommes, Stefan
    State, Radu
    Engel, Thomas
    [J]. 2014 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2014), 2014, : 537 - 543
  • [5] Research on OpenFlow-based SDN technologies
    Zuo, Qing-Yun
    Chen, Ming
    Zhao, Guang-Song
    Xing, Chang-You
    Zhang, Guo-Min
    Jiang, Pei-Cheng
    [J]. Ruan Jian Xue Bao/Journal of Software, 2013, 24 (05): : 1078 - 1097
  • [6] SDN Interactive Manager: An OpenFlow-Based SDN Manager
    Isolani, Pedro Heleno
    Wickboldt, Juliano Araujo
    Both, Cristiano Bonato
    Rochol, Juergen
    Granville, Lisandro Zambenedetti
    [J]. PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 1157 - 1158
  • [7] An OpenFlow-Based Load Balancing Strategy in SDN
    Shi, Xiaojun
    Li, Yangyang
    Xie, Haiyong
    Yang, Tengfei
    Zhang, Linchao
    Liu, Panyu
    Zhang, Heng
    Liang, Zhiyao
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 62 (01): : 385 - 398
  • [8] IRIS: The Openflow-based Recursive SDN Controller
    Lee, Byungjoon
    Park, Sae Hyong
    Shin, Jisoo
    Yang, Sunhee
    [J]. 2014 16TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2014, : 1227 - 1231
  • [9] Security in OpenFlow-based SDN, opportunities and challenges
    Jaouad Benabbou
    Khalid Elbaamrani
    Noureddine Idboufker
    [J]. Photonic Network Communications, 2019, 37 : 1 - 23
  • [10] Security in OpenFlow-based SDN, opportunities and challenges
    Benabbou, Jaouad
    Elbaamrani, Khalid
    Idboufker, Noureddine
    [J]. PHOTONIC NETWORK COMMUNICATIONS, 2019, 37 (01) : 1 - 23