Hop-by-Hop Verification Mechanism of Packet Forwarding Path Oriented to Programmable Data Plane
被引:1
|
作者:
Zeng, Junsan
论文数: 0引用数: 0
h-index: 0
机构:
Beijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R ChinaBeijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
Zeng, Junsan
[1
]
Liu, Ying
论文数: 0引用数: 0
h-index: 0
机构:
Beijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R ChinaBeijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
Liu, Ying
[1
]
Zhang, Weiting
论文数: 0引用数: 0
h-index: 0
机构:
Beijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R ChinaBeijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
Zhang, Weiting
[1
]
Yan, Xincheng
论文数: 0引用数: 0
h-index: 0
机构:
State Key Lab Mobile Network & Mobile Multimedia, Shenzhen 518055, Peoples R China
ZTE Corp, Nanjing 210012, Peoples R ChinaBeijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
Yan, Xincheng
[2
,3
]
Zhou, Na
论文数: 0引用数: 0
h-index: 0
机构:
State Key Lab Mobile Network & Mobile Multimedia, Shenzhen 518055, Peoples R China
ZTE Corp, Nanjing 210012, Peoples R ChinaBeijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
Zhou, Na
[2
,3
]
Jiang, Zhihong
论文数: 0引用数: 0
h-index: 0
机构:
State Key Lab Mobile Network & Mobile Multimedia, Shenzhen 518055, Peoples R China
ZTE Corp, Nanjing 210012, Peoples R ChinaBeijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
Jiang, Zhihong
[2
,3
]
机构:
[1] Beijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
[2] State Key Lab Mobile Network & Mobile Multimedia, Shenzhen 518055, Peoples R China
Attacks against the forwarding path could deviate data packets from the predefined route to achieve ulterior purposes, which has posed a serious threat to the software-defined network. Previous studies attempted to solve this security issue through complex authentication or traffic statistics methods. However, existing schemes have the disadvantages of high bandwidth overhead and high process delay. Hence, this article proposed a lightweight forwarding path verification mechanism based on P4 implementation. First, we deployed inband network telemetry to obtain path information, and then performed the path verification inside each hop in the programmable data plane to ensure that various attacks against forwarding paths could be intercepted. Finally, complete path verification information would convey to the control plane for backup. Corresponding experimental results demonstrate that our mechanism can effectively improve the security of the packet forwarding path with acceptable throughput and delay.