Misreporting Attacks in Software-Defined Networking

被引:2
|
作者
Burke, Quinn [1 ]
McDaniel, Patrick [1 ]
La Porta, Thomas [1 ]
Yu, Mingli [1 ]
He, Ting [1 ]
机构
[1] Penn State Univ, State Coll, PA 16801 USA
来源
SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT I | 2020年 / 335卷
基金
美国国家科学基金会;
关键词
Network security; SDN; Load balancing;
D O I
10.1007/978-3-030-63086-7_16
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Load balancers enable efficient use of network resources by distributing traffic fairly across them. In software-defined networking (SDN), load balancing is most often realized by a controller application that solicits traffic load reports from network switches and enforces load balancing decisions through flow rules. This separation between the control and data planes in SDNs creates an opportunity for an adversary at a compromised switch to misreport traffic loads to influence load balancing. In this paper, we evaluate the ability of such an adversary to control the volume of traffic flowing through a compromised switch by misreporting traffic loads. We use a queuing theoretic approach to model the attack and develop algorithms for misreporting that allow an adversary to tune attack parameters toward specific adversarial goals. We validate the algorithms with a virtual network testbed, finding that through misreporting the adversary can draw nearly all of the load in the subnetwork (+750%, or 85% of the load in the system), or an adversary-desired amount of load (a target load, e.g., +200%) to within 12% error of that target. This is yet another example of how depending on untrustworthy reporting in making control decisions can lead to fundamental security failures.
引用
收藏
页码:276 / 296
页数:21
相关论文
共 50 条
  • [31] Managing Wireless Fog Networks using Software-Defined Networking
    Hakiri, Akram
    Sellami, Bassem
    Patil, Prithviraj
    Berthou, Pascal
    Gokhale, Aniruddha
    2017 IEEE/ACS 14TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2017, : 1149 - 1156
  • [32] HTTP DDoS Flooding Attack Mitigation in Software-Defined Networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2021, E104D (09): : 1496 - 1499
  • [33] Software-defined networking in vehicular networks: A survey
    Mekki, Tesnim
    Jabri, Issam
    Rachedi, Abderrezak
    Chaari, Lamia
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2022, 33 (10)
  • [34] Security in Software-Defined Networking: Threats and Countermeasures
    Zhaogang Shu
    Jiafu Wan
    Di Li
    Jiaxiang Lin
    Athanasios V. Vasilakos
    Muhammad Imran
    Mobile Networks and Applications, 2016, 21 : 764 - 776
  • [35] A Systematic Review of Load Balancing Techniques in Software-Defined Networking
    Belgaum, Mohammad Riyaz
    Musa, Shahrulniza
    Alam, Muhammad Mansoor
    Su'ud, Mazliham Mohd
    IEEE ACCESS, 2020, 8 : 98612 - 98636
  • [36] A new attacks intrusion detection model based on deep learning in Software-Defined Networking Environments
    Yang, Jikun
    2024 4TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND INTELLIGENT SYSTEMS ENGINEERING, MLISE 2024, 2024, : 430 - 436
  • [37] Detection Techniques of Distributed Denial of Service Attacks on Software-Defined Networking Controller-A Review
    Aladaileh, Mohammad A.
    Anbar, Mohammed
    Hasbullah, Iznan H.
    Chong, Yung-Wey
    Sanjalawe, Yousef K.
    IEEE ACCESS, 2020, 8 : 143985 - 143995
  • [38] An Efficient Scheme to Defend Data-to-Control-Plane Saturation Attacks in Software-Defined Networking
    Huang, Xuan-Bo
    Xue, Kai-Ping
    Xing, Yi-Tao
    Hu, Ding-Wen
    Li, Ruidong
    Sun, Qi-Bin
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2022, 37 (04) : 839 - 851
  • [39] Load-Balancing Software-Defined Networking Through Hybrid Routing
    Zhao, Gongming
    Huang, Liusheng
    Li, Ziqiang
    Xu, Hongli
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS, WASA 2017, 2017, 10251 : 96 - 108
  • [40] A Survey on the Contributions of Software-Defined Networking to Traffic Engineering
    Mendiola, Alaitz
    Astorga, Jasone
    Jacob, Eduardo
    Higuero, Marivi
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (02): : 918 - 953