POAGuard: A Defense Mechanism Against Preemptive Table Overflow Attack in Software-Defined Networks

被引:0
|
作者
Liu, Yuming [1 ]
Wang, Yong [1 ]
Feng, Hao [1 ]
机构
[1] Guilin Univ Elect Technol, Sch Comp & Informat Secur, Guilin 541004, Peoples R China
基金
中国国家自然科学基金;
关键词
SDN; flow table overflow; preemptive overflow attack; attack detection;
D O I
10.1109/ACCESS.2023.3330224
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In Software-Defined Networks (SDN), the limited flow table capacity of switches makes them susceptible to flow table overflow attacks, which can lead to performance degradation or network corruption. Prior research has mainly focused on rate-based overflow attacks (ROA), which exhibit varying attack effects depending on the overflow rate. This study introduces a novel attack called the preemptive overflow attack (POA), which exploits flow entry eviction mechanism to preempt the flow entries of normal applications, resulting in amplified performance degradation. Notably, when using the widely deployed Least Frequently Used (LFU) eviction algorithm, POA achieves a significant impact while consuming fewer flow entries than existing ROA methods. Furthermore, the detection of POA remains challenging owing to the lack of distinctive flow features. To mitigate POA, we propose POAGuard as a defense mechanism. POAGuard incorporates a table segmentation method for table management, a score-based eviction algorithm that evicts suspicious flow entries, and a concept drift-based detection method that identifies and defends against POA. Extensive experiments are conducted to verify the effectiveness of POAGuard, and the results demonstrate that POAGuard can effectively defend against POA.
引用
收藏
页码:123659 / 123676
页数:18
相关论文
共 50 条
  • [41] Attack detection analysis in software-defined networks using various machine learning method
    Wang, Yonghong
    Wang, Xiaofeng
    Ariffin, Mazeyanti Mohd
    Abolfathi, Masoumeh
    Alqhatani, Abdulmajeed
    Almutairi, Laila
    COMPUTERS & ELECTRICAL ENGINEERING, 2023, 108
  • [42] Bandwidth Control Mechanism and Extreme Gradient Boosting Algorithm for Protecting Software-Defined Networks Against DDoS Attacks
    Alamri, Hassan A.
    Thayananthan, Vijey
    IEEE ACCESS, 2020, 8 : 194269 - 194288
  • [43] Blockchain-Based Control Plane Attack Detection Mechanisms for Multi-Controller Software-Defined Networks
    Alkhamisi, Abrar
    Katib, Iyad
    Buhari, Seyed M.
    ELECTRONICS, 2024, 13 (12)
  • [44] A Fast and Load-aware Controller Failover Mechanism for Software-Defined Networks
    Fang, Ko-Chih
    Wang, Kuochen
    Wang, Jian-Hong
    2016 10TH INTERNATIONAL SYMPOSIUM ON COMMUNICATION SYSTEMS, NETWORKS AND DIGITAL SIGNAL PROCESSING (CSNDSP), 2016,
  • [45] A batch delivery mechanism of network update in software-defined wide area networks
    Zhang, RongBo
    Li, Xin
    Niu, Jibin
    Wang, Yinqing
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2022, 32 (03)
  • [46] A Software-Defined Traffic Differential Protection Mechanism of Power Grid Communication Networks
    Liu, Chuan
    Xu, Xin
    Tao, Jing
    Liu, Shidong
    PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON ELECTRONICAL, MECHANICAL AND MATERIALS ENGINEERING (ICE2ME 2019), 2019, 181 : 19 - 22
  • [47] Buffering and prioritization in switches for fast processing table-miss packets in software-defined networks
    Lai, Yuan-Cheng
    Legese Hailemariam, Zelalem
    Chen, Yen-Hung
    Kuo, Yi-Ting
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2021, 34 (08)
  • [48] Performance of QoS policies in Software-Defined Networks
    Gomez Manzanares, Juan Felipe
    Pachon de la Cruz, Alvaro
    Madrid Molina, Juan Manuel
    2018 IEEE 10TH LATIN-AMERICAN CONFERENCE ON COMMUNICATIONS (IEEE LATINCOM), 2018,
  • [49] Dynamic vulnerability assessments of software-defined networks
    Deb, Raktim
    Roy, Sudipta
    INNOVATIONS IN SYSTEMS AND SOFTWARE ENGINEERING, 2020, 16 (01) : 45 - 51
  • [50] Rapid Restoration Techniques for Software-Defined Networks
    Malik, Ali
    de Frein, Ruairi
    Aziz, Benjamin
    APPLIED SCIENCES-BASEL, 2020, 10 (10):