Hop-by-Hop Verification Mechanism of Packet Forwarding Path Oriented to Programmable Data Plane

被引:1
|
作者
Zeng, Junsan [1 ]
Liu, Ying [1 ]
Zhang, Weiting [1 ]
Yan, Xincheng [2 ,3 ]
Zhou, Na [2 ,3 ]
Jiang, Zhihong [2 ,3 ]
机构
[1] Beijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
[2] State Key Lab Mobile Network & Mobile Multimedia, Shenzhen 518055, Peoples R China
[3] ZTE Corp, Nanjing 210012, Peoples R China
来源
EMERGING NETWORKING ARCHITECTURE AND TECHNOLOGIES, ICENAT 2022 | 2023年 / 1696卷
关键词
Path verification; SDN; P4; INT; NETWORKS;
D O I
10.1007/978-981-19-9697-9_37
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Attacks against the forwarding path could deviate data packets from the predefined route to achieve ulterior purposes, which has posed a serious threat to the software-defined network. Previous studies attempted to solve this security issue through complex authentication or traffic statistics methods. However, existing schemes have the disadvantages of high bandwidth overhead and high process delay. Hence, this article proposed a lightweight forwarding path verification mechanism based on P4 implementation. First, we deployed inband network telemetry to obtain path information, and then performed the path verification inside each hop in the programmable data plane to ensure that various attacks against forwarding paths could be intercepted. Finally, complete path verification information would convey to the control plane for backup. Corresponding experimental results demonstrate that our mechanism can effectively improve the security of the packet forwarding path with acceptable throughput and delay.
引用
收藏
页码:454 / 466
页数:13
相关论文
共 50 条
  • [21] An Efficient Signcryption Protocol for Hop-by-Hop Data Aggregations in Smart Grids
    Sui, Zhiyuan
    de Meer, Hermann
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2020, 38 (01) : 132 - 140
  • [22] SDAP: A secure Hop-by-hop Data Aggregation Protocol for sensor networks
    Yang, Yi
    Wang, Xinran
    Zhu, Sencun
    Cao, Guohong
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2008, 11 (04)
  • [23] Hop-By-Hop Data Transmitting using EPID to Reduce Iteration Process
    Haritha, M.
    Allan, L.
    Hari, C. S.
    Venkatesh, S. J. Hari
    Nandhakuma, S. R.
    BIOSCIENCE BIOTECHNOLOGY RESEARCH COMMUNICATIONS, 2020, 13 (04): : 8 - 11
  • [24] Joint routing and scheduling optimization in arbitrary ad hoc networks: Comparison of cooperative and hop-by-hop forwarding
    Capone, Antonio
    Gualandi, Stefano
    Yuan, Di
    AD HOC NETWORKS, 2011, 9 (07) : 1256 - 1269
  • [25] Hop-by-hop Control for Reliable Data Dissemination in Wireless Sensor Networks
    Park, Hosung
    Kim, Taehee
    Lee, Jeongcheol
    Jin, Min-Sook
    Kim, Sang-Ha
    ISADS 2009: 2009 INTERNATIONAL SYMPOSIUM ON AUTONOMOUS DECENTRALIZED SYSTEMS, PROCEEDINGS, 2009, : 317 - 322
  • [26] An extended Hop-by-hop Interest shaping mechanism for Content-Centric Networking
    Rozhnova, Natalya
    Fdida, Serge
    2014 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2014), 2014, : 1198 - 1204
  • [27] A hop-by-hop dynamic distributed multipath routing mechanism for link state network
    Geng, Haijun
    Shi, Xingang
    Wang, Zhiliang
    Yin, Xin
    COMPUTER COMMUNICATIONS, 2018, 116 : 225 - 239
  • [28] Active multicast congestion control with hop-by-hop credit-based mechanism
    Lee, Jong-Kwon
    Kim, Tag Gon
    2002, Institute of Electronics, Information and Communication, Engineers, IEICE (E85-B)
  • [29] Active multicast congestion control with hop-by-hop credit-based mechanism
    Lee, JK
    Kim, TG
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2002, E85B (03) : 614 - 622
  • [30] Dynamic load distribution with hop-by-hop forwarding based on max-min one-way delay
    Fei Chen
    ChunMing Wu
    Bin Wang
    YaGuan Qian
    XiaoChun Wu
    Science China Information Sciences, 2014, 57 : 1 - 12