Hop-by-Hop Verification Mechanism of Packet Forwarding Path Oriented to Programmable Data Plane

被引:1
|
作者
Zeng, Junsan [1 ]
Liu, Ying [1 ]
Zhang, Weiting [1 ]
Yan, Xincheng [2 ,3 ]
Zhou, Na [2 ,3 ]
Jiang, Zhihong [2 ,3 ]
机构
[1] Beijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
[2] State Key Lab Mobile Network & Mobile Multimedia, Shenzhen 518055, Peoples R China
[3] ZTE Corp, Nanjing 210012, Peoples R China
来源
EMERGING NETWORKING ARCHITECTURE AND TECHNOLOGIES, ICENAT 2022 | 2023年 / 1696卷
关键词
Path verification; SDN; P4; INT; NETWORKS;
D O I
10.1007/978-981-19-9697-9_37
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Attacks against the forwarding path could deviate data packets from the predefined route to achieve ulterior purposes, which has posed a serious threat to the software-defined network. Previous studies attempted to solve this security issue through complex authentication or traffic statistics methods. However, existing schemes have the disadvantages of high bandwidth overhead and high process delay. Hence, this article proposed a lightweight forwarding path verification mechanism based on P4 implementation. First, we deployed inband network telemetry to obtain path information, and then performed the path verification inside each hop in the programmable data plane to ensure that various attacks against forwarding paths could be intercepted. Finally, complete path verification information would convey to the control plane for backup. Corresponding experimental results demonstrate that our mechanism can effectively improve the security of the packet forwarding path with acceptable throughput and delay.
引用
收藏
页码:454 / 466
页数:13
相关论文
empty
未找到相关数据