ATTAIN: An Attack Injection Framework for Software-Defined Networking

被引:11
作者
Ujcich, Benjamin E. [1 ,2 ]
Thakore, Uttam [1 ,3 ]
Sanders, William H. [1 ,2 ]
机构
[1] Univ Illinois, Informat Trust Inst, Urbana, IL 61801 USA
[2] Univ Illinois, Dept Elect & Comp Engn, Urbana, IL 61801 USA
[3] Univ Illinois, Dept Comp Sci, Urbana, IL USA
来源
2017 47TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN) | 2017年
关键词
D O I
10.1109/DSN.2017.59
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has recently attracted interest as a way to provide cyber resiliency because of its programmable and logically centralized nature. However, the security of the SDN architecture itself against malicious attacks is not well understood and must be ensured in order to provide cyber resiliency to systems that use SDNs. In this paper, we present ATTAIN, an attack injection framework for OpenFlow-based SDN architectures. First, we define an attack model that relates system components to an attacker's capability to influence control plane behavior. Second, we define an attack language for writing control plane attacks that can be used to evaluate SDN implementations. Third, we describe an attack injector architecture that actuates attacks in networks. Finally, we evaluate our framework with an enterprise network case study by writing and running attacks with popular SDN controllers.
引用
收藏
页码:567 / 578
页数:12
相关论文
共 27 条
[1]  
[Anonymous], 2009, OpenFlow switch specifications
[2]  
[Anonymous], 2013, P 2 ACM SIGCOMM WORK, DOI DOI 10.1145/2491185.2491199
[3]  
[Anonymous], 2012, OPENFLOW SWITCH SPEC
[4]  
[Anonymous], 2014, P 3 WORKSH HOT TOP S, DOI DOI 10.1145/2620728.2620744
[5]  
[Anonymous], 2012, Software-Defined Networking: The New Norm for Networks
[6]  
[Anonymous], 2013, NETWORK PROTOCOLS IC
[7]  
[Anonymous], 2013, SSRN, DOI [DOI 10.2139/SSRN.2304426, 10.2139/ssrn.2304426]
[8]   Vulnerability Discovery with Attack Injection [J].
Antunes, Joao ;
Neves, Nuno ;
Correia, Miguel ;
Verissimo, Paulo ;
Neves, Rui .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2010, 36 (03) :357-370
[9]   GENI: A federated testbed for innovative network experiments [J].
Berman, Mark ;
Chase, Jeffrey S. ;
Landweber, Lawrence ;
Nakao, Akihiro ;
Ott, Max ;
Raychaudhuri, Dipankar ;
Ricci, Robert ;
Seskar, Ivan .
COMPUTER NETWORKS, 2014, 61 :5-23
[10]  
Big Switch Networks, 2016, PROJ FLOODL OP SOURC