A Novel Mechanism for Detection of Address Resolution Protocol Spoofing Attacks in Large-Scale Software-Defined Networks

被引:3
作者
Patrice, Laurent [1 ]
Sinde, Ramadhani [1 ]
Leo, Judith [1 ]
机构
[1] Nelson Mandela African Inst Sci & Technol, Sch Computat & Commun Sci & Engn, Arusha 44740, Tanzania
关键词
Scalability; Monitoring; Protocols; Internet; Servers; Computer architecture; Process control; Software defined networking; Network security; Decentralized control; ARP cache poisoning; ARP spoofing; software-define network; network security; distributed controllers; TAXONOMY; SDN; ARP;
D O I
10.1109/ACCESS.2024.3409679
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Address Resolution Protocol (ARP) spoofing has been a long-standing problem with no clear remedy until now. The attacks can be launched easily utilizing an enormous number of publicly available tools on the web; however, they are extremely tough to counterattack due to ARP's stateless nature for not authenticating ARP replies for a subsequent request. Previous studies have demonstrated significant efforts to counterattack these assaults in Software-Defined Networks (SDN); however, much effort has been focused solely on detecting the assaults, with little effort being made to address performance bottlenecks, scalability, and Single Point of Failure (SPOF) issues in large-scale networks. In this study, we focus on developing ARP spoofing attacks detection mechanism in large-scale SDN that is immune to SPOF and provides enhanced network performance and scalability. The main purpose is to enable controllers to intercept and analyze all incoming ARP packets, learn address mappings, and store them in the application's memory to be used as a basis for ongoing ARP cache comparisons while maintaining a global cache in a controller. To achieve the goal of this study, a simulation experiment in a closed network environment was undertaken to precisely monitor network traffic and result patterns. Mininet and the Open Network Operating System were used to implement the data plane and OpenFlow controllers. The results show that, the proposed solution is resistant to ARP spoofing attacks, with an average detection and mitigation time of 4.3 and 26.19 milliseconds, respectively. Further significant improvements have been observed in alleviating SPOF and performance bottlenecks.
引用
收藏
页码:80255 / 80265
页数:11
相关论文
共 35 条
[1]   Distributed controller clustering in software defined networks [J].
Abdelaziz, Ahmed ;
Fong, Ang Tan ;
Geni, Abdullah ;
Garba, Usman ;
Khan, Suleman ;
Akhunzada, Adnan ;
Talebian, Hamid ;
Choo, Kim-Kwang Raymond .
PLOS ONE, 2017, 12 (04)
[2]   A novel mechanism to handle address spoofing attacks in SDN based IoT [J].
Aldabbas, Hamza ;
Amin, Rashid .
CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2021, 24 (04) :3011-3026
[3]   DSF: A Distributed SDN Control Plane Framework for the East/West Interface [J].
Almadani, Basem ;
Beg, Abdurrahman ;
Mahmoud, Ashraf .
IEEE ACCESS, 2021, 9 :26735-26754
[4]  
Alzuwaini M. H., 2021, Iraqi J. Electr. Electron. Eng., V17, P125
[5]   Distributed SDN Control: Survey, Taxonomy, and Challenges [J].
Bannour, Fetia ;
Souihi, Sami ;
Mellouk, Abdelhamid .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (01) :333-354
[6]   Software-defined networking (SDN): a survey [J].
Benzekki, Kamal ;
El Fergougui, Abdeslam ;
Elalaoui, Abdelbaki Elbelrhiti .
SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) :5803-5833
[7]   Address Resolution Protocol Based Attacks: Prevention and Detection Schemes [J].
Christopher, D. Francis Xavier ;
Divya, C. .
PROCEEDING OF THE INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS, BIG DATA AND IOT (ICCBI-2018), 2020, 31 :247-256
[8]  
Current State of Internet Growth and Usage in Saudi Arabia and Its Ability to Support E-Commerce Development, 2017, Journal of Advanced Management Science, V5, P127, DOI [10.18178/joams.5.2.127-132, 10.18178/joams.5.2.127-132, DOI 10.18178/JOAMS.5.2.127-132, https://doi.org/10.18178/joams.5.2.127-132]
[9]  
Galal AA, 2022, INT J ADV COMPUT SC, V13, P377
[10]   Implementing an intrusion detection and prevention system using Software-Defined Networking: Defending against ARP spoofing attacks and Blacklisted MAC Addresses [J].
Girdler, Thomas ;
Vassilakis, Vassilios G. .
COMPUTERS & ELECTRICAL ENGINEERING, 2021, 90