POAGuard: A Defense Mechanism Against Preemptive Table Overflow Attack in Software-Defined Networks

被引:0
|
作者
Liu, Yuming [1 ]
Wang, Yong [1 ]
Feng, Hao [1 ]
机构
[1] Guilin Univ Elect Technol, Sch Comp & Informat Secur, Guilin 541004, Peoples R China
基金
中国国家自然科学基金;
关键词
SDN; flow table overflow; preemptive overflow attack; attack detection;
D O I
10.1109/ACCESS.2023.3330224
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In Software-Defined Networks (SDN), the limited flow table capacity of switches makes them susceptible to flow table overflow attacks, which can lead to performance degradation or network corruption. Prior research has mainly focused on rate-based overflow attacks (ROA), which exhibit varying attack effects depending on the overflow rate. This study introduces a novel attack called the preemptive overflow attack (POA), which exploits flow entry eviction mechanism to preempt the flow entries of normal applications, resulting in amplified performance degradation. Notably, when using the widely deployed Least Frequently Used (LFU) eviction algorithm, POA achieves a significant impact while consuming fewer flow entries than existing ROA methods. Furthermore, the detection of POA remains challenging owing to the lack of distinctive flow features. To mitigate POA, we propose POAGuard as a defense mechanism. POAGuard incorporates a table segmentation method for table management, a score-based eviction algorithm that evicts suspicious flow entries, and a concept drift-based detection method that identifies and defends against POA. Extensive experiments are conducted to verify the effectiveness of POAGuard, and the results demonstrate that POAGuard can effectively defend against POA.
引用
收藏
页码:123659 / 123676
页数:18
相关论文
共 50 条
  • [31] A QoS-guaranteed intelligent routing mechanism in software-defined networks
    Sun, Weifeng
    Wang, Zun
    Zhang, Guanghao
    COMPUTER NETWORKS, 2021, 185
  • [32] Advancing Software-Defined Networks: A Survey
    Cox, Jacob, Jr.
    Chuang, Joaquin
    Donvan, Sean
    Ivey, Jared
    Clarx, Russel J.
    Riley, George
    Owen, Henry L., III
    IEEE ACCESS, 2017, 5 : 25487 - 25526
  • [33] A QoS-guaranteed intelligent routing mechanism in software-defined networks
    Sun, Weifeng
    Wang, Zun
    Zhang, Guanghao
    COMPUTER NETWORKS, 2021, 185
  • [34] Load Balancing for Software-Defined Networks
    Mulla, Mohammed Moin
    Raikar, M. M.
    Meghana, M. K.
    Shetti, Nagashree S.
    Madhu, R. K.
    EMERGING RESEARCH IN ELECTRONICS, COMPUTER SCIENCE AND TECHNOLOGY, ICERECT 2018, 2019, 545 : 235 - 244
  • [35] A QoS-guaranteed intelligent routing mechanism in software-defined networks
    Sun, Weifeng
    Wang, Zun
    Zhang, Guanghao
    COMPUTER NETWORKS, 2021, 185
  • [36] An Anonymization Service for Software-Defined Networks
    Bomfim, Leonardo H. S.
    Salgueiro, Edilayne M.
    Salgueiro, Ricardo J. P. de B.
    2018 XLIV LATIN AMERICAN COMPUTER CONFERENCE (CLEI 2018), 2018, : 698 - 707
  • [37] The Global Flow Table Based on The Software-Defined Networking
    Ren, Qiuzheng
    Qiu, Xiaofeng
    Chen, Pengcheng
    Liang, XiaoDong
    2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATION PROBLEM-SOLVING (ICCP), 2015, : 264 - 267
  • [38] Dynamic Routing in Software-Defined Networks
    Mulla, Mohammed Moin
    Khot, Akshay
    Patil, Anusha
    Chandani, D. G.
    EMERGING RESEARCH IN ELECTRONICS, COMPUTER SCIENCE AND TECHNOLOGY, ICERECT 2018, 2019, 545 : 1027 - 1037
  • [39] A QoS-guaranteed intelligent routing mechanism in software-defined networks
    Sun, Weifeng
    Wang, Zun
    Zhang, Guanghao
    COMPUTER NETWORKS, 2021, 185
  • [40] EarlyDrop: A Trade-off Driven DDoS Defense Mechanism for Software-defined Infrastructures
    Bauer, Robert
    Heseding, Hauke
    Flittner, Matthias
    2017 IEEE 42ND CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2017, : 207 - 210