On the fine-grained fingerprinting threat to software-defined networks

被引:8
|
作者
Hou, Jianwei [1 ]
Zhang, Minjian [1 ]
Zhang, Ziqi [1 ]
Shi, Wenchang [1 ]
Qin, Bo [1 ]
Liang, Bin [1 ]
机构
[1] Renmin Univ China, Sch Informat, Beijing, Peoples R China
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2020年 / 107卷
基金
北京市自然科学基金; 中国国家自然科学基金;
关键词
SDN; Fingerprinting; Timing attacks; Information disclosure; Mitigation strategies; SECURITY;
D O I
10.1016/j.future.2020.01.046
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Software-defined networking (SDN) is an emerging networking technology, which has attracted wide attention from academia and industry, playing a key role in enabling techniques of the 5th generation wireless systems (5G). The fundamental characteristic of SDN is that it decouples the control plane from the data plane, which can provide flexibility and programmability for 5G. Unfortunately, the separation of the two planes becomes a potential attack surface as well, which enables adversaries to fingerprint and attack the SDNs. Existing work showed the possibility of fingerprinting an SDN with time-based features. However, they are coarse-grained. This paper proposes a fine-grained fingerprinting approach that reveals the much more severe threats to SDN security and explores the mitigation strategies. By analyzing network packets, the approach can dig out sensitive and control-related information, i.e., match fields of SDN flow rules. The match fields of flow rules can be used to infer the type of an SDN controller and the security policy of an SDN network. With sensitive configuration information, adversaries can launch more targeted and destructive attacks against an SDN. We implement our approach in both simulated and physical environments with different kinds of SDN controllers to verify the effectiveness of our concept. Experimental results demonstrate the feasibility to obtain fine-grained and highly sensitive information in SDN, and hence reveal the high risk of information disclosure in SDN and severe threats of attacks against SDN. To mitigate the fine-grained fingerprinting threat we have revealed, we explore a lightweight countermeasure trying to hide the sensitive time-based features of SDN networks. Implementation and evaluation demonstrate that our countermeasure can play a role in mitigating the risk of SDN control information leakage with only minor overheads. (C) 2020 Elsevier B.V. All rights reserved.
引用
收藏
页码:485 / 497
页数:13
相关论文
共 50 条
  • [1] Fine-Grained Fingerprinting Threats to Software-Defined Networks
    Zhang, Minjian
    Hou, Jianwei
    Zhang, Ziqi
    Shi, Wenchang
    Qin, Bo
    Liang, Bin
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 128 - 135
  • [2] Fine-Grained Bandwidth Allocation in Software-Defined Networks
    Khumngoen, Wisarut
    Putthividhya, Wanida
    Tan-Anannuwat, Vasuwat
    2016 20TH INTERNATIONAL COMPUTER SCIENCE AND ENGINEERING CONFERENCE (ICSEC), 2016,
  • [3] A Fine-Grained Video Traffic Control Mechanism in Software-Defined Networks
    Huang, Jun
    Duan, Qiang
    Xing, Cong-Cong
    Gu, Bo
    Wang, Guodong
    Zeadally, Sherali
    Baker, Erich
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (03): : 3501 - 3515
  • [4] Designing Fine-Grained Access Control for Software-Defined Networks Using Private Blockchain
    Chattaraj, Durbadal
    Bera, Basudeb
    Das, Ashok Kumar
    Rodrigues, Joel J. P. C.
    Park, Youngho
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (02) : 1542 - 1559
  • [5] On the Fingerprinting of Software-Defined Networks
    Cui, Heng
    Karame, Ghassan O.
    Klaedtke, Felix
    Bifulco, Roberto
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2016, 11 (10) : 2160 - 2173
  • [6] Fingerprinting Software-defined Networks
    Bifulco, Roberto
    Cui, Heng
    Karame, Ghassan O.
    Klaedtke, Felix
    2015 IEEE 23RD INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2015, : 453 - 459
  • [7] Rethinking Fine-Grained Measurement From Software-Defined Perspective: A Survey
    Zheng, Hao
    Jiang, Yanan
    Tian, Chen
    Cheng, Long
    Huang, Qun
    Li, Weichao
    Wang, Yi
    Huang, Qianyi
    Zheng, Jiaqi
    Xia, Rui
    Wang, Yi
    Dou, Wanchun
    Chen, Guihai
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2022, 15 (06) : 3649 - 3667
  • [8] Towards a Software-Defined, Fine-Grained QoS Framework for 5G and Beyond Networks
    Zhang, Zhi-Li
    Dayalan, Udhaya Kumar
    Ramadan, Eman
    Salo, Timothy J.
    PROCEEDINGS OF THE ACM SIGCOMM 2021 WORKSHOP ON NETWORK-APPLICATION INTEGRATION (NAI '21), 2021, : 7 - 13
  • [9] SLA-Aware Fine-Grained QoS Provisioning for Multi-Tenant Software-Defined Networks
    Li, Gaolei
    Wu, Jun
    Li, Jianhua
    Zhou, Zhenyu
    Guo, Longhua
    IEEE ACCESS, 2018, 6 : 159 - 170
  • [10] Toward Real-time and Fine-grained Monitoring of Software-defined Networking in the Cloud
    Zhao, Dongfang
    PROCEEDINGS OF 2016 IEEE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2016, : 884 - 887