A proactive defense method against eavesdropping attack in SDN-based storage environment

被引:0
|
作者
Liu, Yuming [1 ]
Wang, Yong [1 ]
Feng, Hao [1 ]
机构
[1] Guilin Univ Elect Technol, Sch Comp & Informat Secur, Guilin 541004, Peoples R China
来源
CYBERSECURITY | 2024年 / 7卷 / 01期
基金
中国国家自然科学基金;
关键词
SDN; Storage center; Eavesdropping attack; Moving target defense; End hopping; ROUTE MUTATION; NETWORK; MECHANISM; FLOW;
D O I
10.1186/s42400-024-00255-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The integration of Software-Defined Networking (SDN) in storage centers aims to enhance storage performance. However, this integration also introduces new concerns, particularly the potential eavesdropping attacks that pose a substantial risk to data privacy. By issuing flow tables (e.g., via compromised SDN switches), attackers can conveniently collect target traffic and extract confidential information with session reassembly methods. To proactively mitigate such attacks by preventing session reassembly, various moving target defense methods, such as end hopping, have been proposed. However, this study uncovers several deficiencies within existing end hopping methods. To address these deficiencies, we propose a novel linkage-field-based self-synchronizing end hopping method, which obfuscates end information (e.g., IP, Port) and linkage fields (e.g., sequence number and ID number) without third-party assistance. Furthermore, to counter the potential invalidation of end hopping methods resulting from brute-force reassembly of a small number of sessions, we propose a fake segment injection method. Extensive experiments have been conducted both in simulation and real-world environment to evaluate the effectiveness of our proposed methods. The results demonstrate that our proposed methods can effectively defend against eavesdropping attacks with acceptable performance overhead.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] SDN-based Path Hopping Communication Against Eavesdropping Attack
    Zhang, Chuanhao
    Bu, Youjun
    Zhao, Zheng
    OPTICAL COMMUNICATION AND OPTICAL FIBER SENSORS AND OPTICAL MEMORIES FOR BIG DATA STORAGE, 2016, 10158
  • [2] SDN-Based Double Hopping Communication against Sniffer Attack
    Zhao, Zheng
    Gong, Daofu
    Lu, Bin
    Liu, Fenlin
    Zhang, Chuanhao
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2016, 2016
  • [3] Efficient Distributed Denial-of-Service Attack Defense in SDN-Based Cloud
    Phan, Trung, V
    Park, Minho
    IEEE ACCESS, 2019, 7 : 18701 - 18714
  • [4] SDN-based cyber defense: A survey
    Yurekten, Ozgur
    Demirci, Mehmet
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 115 : 126 - 149
  • [5] An SDN-Based IP Hopping Communication Scheme against Scanning Attack
    Zhao, Zheng
    Liu, Fenlin
    Gong, Daofu
    Chen, Lin
    Xiang, Fei
    Li, Yan
    2017 IEEE 9TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN), 2017, : 559 - 564
  • [6] Implementation of an SDN-based Security Defense Mechanism Against DDoS Attacks
    Lin, Hsiao-Chung
    Wang, Ping
    JOINT 2016 INTERNATIONAL CONFERENCE ON ECONOMICS AND MANAGEMENT ENGINEERING (ICEME 2016) AND INTERNATIONAL CONFERENCE ON ECONOMICS AND BUSINESS MANAGEMENT (EBM 2016), 2016, : 377 - 383
  • [7] SDN-Based Network Intrusion Detection as DDoS defense system for Virtualization Environment
    Usman, Saifudin
    Winarno, Idris
    Sudarsono, Amang
    EMITTER-INTERNATIONAL JOURNAL OF ENGINEERING TECHNOLOGY, 2021, 9 (02) : 252 - 267
  • [8] SDN-based hybrid honeypot for attack capture
    Wang, He
    Wu, Bin
    PROCEEDINGS OF 2019 IEEE 3RD INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2019), 2019, : 1602 - 1606
  • [9] SDN-based SYN Flooding Defense in Cloud
    Mahrach, Safaa
    El Mir, Iman
    Haqiq, Abdelkrim
    Huang, Dijiang
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2018, 13 (01): : 30 - 39
  • [10] Defending Against New-Flow Attack in SDN-Based Internet of Things
    Xu, Tong
    Gao, Deyun
    Dong, Ping
    Zhang, Hongke
    Foh, Chuan Heng
    Chao, Han-Chieh
    IEEE ACCESS, 2017, 5 : 3431 - 3443