Leveraging SDN to Improve the Security of DHCP

被引:10
作者
Cox, Jacob H., Jr. [1 ]
Clark, Russell J. [2 ]
Owen, Henry L., III [1 ]
机构
[1] Georgia Inst Technol, Sch Elect & Comp Engn, Atlanta, GA 30332 USA
[2] Georgia Inst Technol, Coll Comp, Atlanta, GA 30332 USA
来源
SDN-NFV SECURITY'16: PROCEEDINGS OF THE 2016 ACM INTERNATIONAL WORKSHOP ON SECURITY IN SOFTWARE DEFINED NETWORKS & NETWORK FUNCTION VIRTUALIZATION | 2016年
关键词
DHCP; IDPS; Network Security; Programmable Networks; Rogue Servers; SDN;
D O I
10.1145/2876019.2876028
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Current State of the art technologies for detecting and neutralizing rogue DHCP servers are tediously complex and prone to error. Network operators can spend hours (even days) before realizing that a rogue server is affecting their network. Additionally, once network operators suspect that a rogue server is active on their network, even more hours can be spent finding the server's MAC address and preventing it from affecting other clients. Not only are such methods slow to eliminate rogue servers, they are also likely to affect other clients as network operators shutdown services while attempting to locate the server. In this paper, we present Network Flow Guard (NFG), a simple security application that utilizes the software defined networking (SDN) paradigm of programmable networks to detect and disable rogue servers before they are able to affect network clients. Consequently, the key contributions of NFG are its modular approach and its automated detection/prevention of rogue DHCP servers, which is accomplished with little impact to network architecture, protocols, and network operators.
引用
收藏
页码:35 / 38
页数:4
相关论文
共 12 条
[1]  
[Anonymous], P 13 ACM WORKSH HOT
[2]  
Droms R., 1997, RFC2131
[3]   The Road to SDN: An Intellectual History of Programmable Networks [J].
Feamster, Nick ;
Rexford, Jennifer ;
Zegura, Ellen .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (02) :87-98
[4]  
Lantz Bob, 2010, ACM HOTNETS, P19, DOI 10.1145/1868447.1868466
[5]   OpenFlow: Enabling innovation in campus networks [J].
McKeown, Nick ;
Anderson, Tom ;
Balakrishnan, Hari ;
Parulkar, Guru ;
Peterson, Larry ;
Rexford, Jennifer ;
Shenker, Scott ;
Turner, Jonathan .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2008, 38 (02) :69-74
[6]  
Meraki C., 2015, TRACKING DOWN ROGUE
[7]  
O'Connor D., 2014, DHCP SNOOPING FILTER
[8]  
O'Connor T., 2015, COMMUNICATION
[9]  
Oconnor T., 2013, FIND ROGUE DHCP SERV
[10]  
Reich Joshua., 2013, USENIX LOGIN, V38, P128