Misreporting Attacks in Software-Defined Networking

被引:2
|
作者
Burke, Quinn [1 ]
McDaniel, Patrick [1 ]
La Porta, Thomas [1 ]
Yu, Mingli [1 ]
He, Ting [1 ]
机构
[1] Penn State Univ, State Coll, PA 16801 USA
来源
SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT I | 2020年 / 335卷
基金
美国国家科学基金会;
关键词
Network security; SDN; Load balancing;
D O I
10.1007/978-3-030-63086-7_16
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Load balancers enable efficient use of network resources by distributing traffic fairly across them. In software-defined networking (SDN), load balancing is most often realized by a controller application that solicits traffic load reports from network switches and enforces load balancing decisions through flow rules. This separation between the control and data planes in SDNs creates an opportunity for an adversary at a compromised switch to misreport traffic loads to influence load balancing. In this paper, we evaluate the ability of such an adversary to control the volume of traffic flowing through a compromised switch by misreporting traffic loads. We use a queuing theoretic approach to model the attack and develop algorithms for misreporting that allow an adversary to tune attack parameters toward specific adversarial goals. We validate the algorithms with a virtual network testbed, finding that through misreporting the adversary can draw nearly all of the load in the subnetwork (+750%, or 85% of the load in the system), or an adversary-desired amount of load (a target load, e.g., +200%) to within 12% error of that target. This is yet another example of how depending on untrustworthy reporting in making control decisions can lead to fundamental security failures.
引用
收藏
页码:276 / 296
页数:21
相关论文
共 50 条
  • [21] Survey on Measurement Methods in Software-defined Networking
    Dai M.
    Cheng G.
    Zhou Y.-Y.
    Ruan Jian Xue Bao/Journal of Software, 2019, 30 (06): : 1853 - 1874
  • [22] Data Protection Intents for Software-Defined Networking
    Ujcich, Benjamin E.
    Sanders, William H.
    PROCEEDINGS OF THE 2019 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2019), 2019, : 271 - 275
  • [23] Security Challenges and Opportunities of Software-Defined Networking
    Dacier, Marc C.
    Koenig, Hartmut
    Cwalinski, Radoslaw
    Kargl, Frank
    Dietrich, Sven
    IEEE SECURITY & PRIVACY, 2017, 15 (02) : 96 - 100
  • [24] Toward manageable middleboxes in software-defined networking
    Zadkhosh, Ehsan
    Bahramgiri, Hossein
    Sabaei, Masoud
    ETRI JOURNAL, 2020, 42 (02) : 186 - 195
  • [25] A survey on network forwarding in Software-Defined Networking
    Yang, Liang
    Ng, Bryan
    Seah, Winston K. G.
    Groves, Lindsay
    Singh, Deepak
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 176
  • [26] A Systematic Treat Model for Software-Defined Networking
    Zhang, Wenbin
    Wu, Zehui
    Wei, Qiang
    Yuan, Huijie
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2021, 15 (02) : 580 - 599
  • [27] Policy Authoring for Software-Defined Networking Management
    Machado, Cristian Cleder
    Wickboldt, Juliano Araujo
    Granville, Lisandro Zambenedetti
    Schaeffer-Filho, Alberto
    PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 216 - 224
  • [28] Software-Defined Vehicular Networking: Opportunities and Challenges
    Cardona, Nelson
    Coronado, Estefania
    Latre, Steven
    Riggio, Roberto
    Marquez-Barja, Johann M.
    IEEE ACCESS, 2020, 8 : 219971 - 219995
  • [29] How to use Software-Defined Networking to Improve Security - a Survey
    Proenca, Jorge
    Cruz, Tiago
    Monteiro, Edmundo
    Simoes, Paulo
    PROCEEDINGS OF THE 14TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS-2015), 2015, : 220 - 228
  • [30] Load Distribution of Software-Defined Networking Based on Controller Performance
    Konglar, Kanok
    Somchit, Yuthapong
    2018 15TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER SCIENCE AND SOFTWARE ENGINEERING (JCSSE), 2018, : 115 - 120