Misreporting Attacks in Software-Defined Networking

被引:2
|
作者
Burke, Quinn [1 ]
McDaniel, Patrick [1 ]
La Porta, Thomas [1 ]
Yu, Mingli [1 ]
He, Ting [1 ]
机构
[1] Penn State Univ, State Coll, PA 16801 USA
来源
SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT I | 2020年 / 335卷
基金
美国国家科学基金会;
关键词
Network security; SDN; Load balancing;
D O I
10.1007/978-3-030-63086-7_16
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Load balancers enable efficient use of network resources by distributing traffic fairly across them. In software-defined networking (SDN), load balancing is most often realized by a controller application that solicits traffic load reports from network switches and enforces load balancing decisions through flow rules. This separation between the control and data planes in SDNs creates an opportunity for an adversary at a compromised switch to misreport traffic loads to influence load balancing. In this paper, we evaluate the ability of such an adversary to control the volume of traffic flowing through a compromised switch by misreporting traffic loads. We use a queuing theoretic approach to model the attack and develop algorithms for misreporting that allow an adversary to tune attack parameters toward specific adversarial goals. We validate the algorithms with a virtual network testbed, finding that through misreporting the adversary can draw nearly all of the load in the subnetwork (+750%, or 85% of the load in the system), or an adversary-desired amount of load (a target load, e.g., +200%) to within 12% error of that target. This is yet another example of how depending on untrustworthy reporting in making control decisions can lead to fundamental security failures.
引用
收藏
页码:276 / 296
页数:21
相关论文
共 50 条
  • [41] The Global Flow Table Based on The Software-Defined Networking
    Ren, Qiuzheng
    Qiu, Xiaofeng
    Chen, Pengcheng
    Liang, XiaoDong
    2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATION PROBLEM-SOLVING (ICCP), 2015, : 264 - 267
  • [42] Software-Defined Networking Paradigms in Wireless Networks: A Survey
    Jagadeesan, Nachikethas A.
    Krishnamachari, Bhaskar
    ACM COMPUTING SURVEYS, 2015, 47 (02)
  • [43] Maturing of OpenFlow and Software-defined Networking through deployments
    Kobayashi, Masayoshi
    Seetharaman, Srini
    Parulkar, Guru
    Appenzeller, Guido
    Little, Joseph
    van Reijendam, Johan
    Weissmann, Paul
    McKeown, Nick
    COMPUTER NETWORKS, 2014, 61 : 151 - 175
  • [44] A Novel Dynamic Software-Defined Networking Approach to Neutralize Traffic Burst
    Sharma, Aakanksha
    Balasubramanian, Venki
    Kamruzzaman, Joarder
    COMPUTERS, 2023, 12 (07)
  • [45] Load Balancing in the Fog of Things Platforms through Software-Defined Networking
    Batista, Ernando
    Figueiredo, Gustavo
    Peixoto, Maycon
    Serrano, Martin
    Prazeres, Cassio
    IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY, 2018, : 1785 - 1791
  • [46] Boundary Protection System Based on Software-Defined Networking
    Cao, Lihui
    Zhu, Xiaoming
    Xu, Shubin
    Zhang, Linjie
    2018 IEEE 18TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY (ICCT), 2018, : 1291 - 1296
  • [47] Suppression of Malicious Code Propagation in Software-Defined Networking
    Li, Fengjiao
    Ren, Jianguo
    WIRELESS PERSONAL COMMUNICATIONS, 2024, 135 (01) : 493 - 516
  • [48] Software-Defined Named Data Networking in Literature: A Review
    Alhawas, Albatool
    Belghith, Abdelfettah
    FUTURE INTERNET, 2024, 16 (08)
  • [49] A Software-Defined Networking Architecture for Aerial Network Optimization
    Iqbal, Hammad
    Ma, Jamie
    Stranc, Kenneth
    Palmer, Kenneth
    Benbenek, Peter
    2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 151 - 155
  • [50] Traffic Engineering in Software-Defined Networking: Measurement and Management
    Shu, Zhaogang
    Wan, Jiafu
    Lin, Jiaxiang
    Wang, Shiyong
    Li, Di
    Rho, Seungmin
    Yang, Changcai
    IEEE ACCESS, 2016, 4 : 3246 - 3256