A proactive defense method against eavesdropping attack in SDN-based storage environment

被引:0
|
作者
Liu, Yuming [1 ]
Wang, Yong [1 ]
Feng, Hao [1 ]
机构
[1] Guilin Univ Elect Technol, Sch Comp & Informat Secur, Guilin 541004, Peoples R China
来源
CYBERSECURITY | 2024年 / 7卷 / 01期
基金
中国国家自然科学基金;
关键词
SDN; Storage center; Eavesdropping attack; Moving target defense; End hopping; ROUTE MUTATION; NETWORK; MECHANISM; FLOW;
D O I
10.1186/s42400-024-00255-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The integration of Software-Defined Networking (SDN) in storage centers aims to enhance storage performance. However, this integration also introduces new concerns, particularly the potential eavesdropping attacks that pose a substantial risk to data privacy. By issuing flow tables (e.g., via compromised SDN switches), attackers can conveniently collect target traffic and extract confidential information with session reassembly methods. To proactively mitigate such attacks by preventing session reassembly, various moving target defense methods, such as end hopping, have been proposed. However, this study uncovers several deficiencies within existing end hopping methods. To address these deficiencies, we propose a novel linkage-field-based self-synchronizing end hopping method, which obfuscates end information (e.g., IP, Port) and linkage fields (e.g., sequence number and ID number) without third-party assistance. Furthermore, to counter the potential invalidation of end hopping methods resulting from brute-force reassembly of a small number of sessions, we propose a fake segment injection method. Extensive experiments have been conducted both in simulation and real-world environment to evaluate the effectiveness of our proposed methods. The results demonstrate that our proposed methods can effectively defend against eavesdropping attacks with acceptable performance overhead.
引用
收藏
页数:19
相关论文
共 50 条
  • [21] An SDN-based DDoS defense approach using route obfuscation
    Hormozi, Mohammad
    Erfani, S. Hossein
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (01):
  • [22] SDN-based solutions for Moving Target Defense network protection
    Kampanakis, Panos
    Perros, Harry
    Beyene, Tsegereda
    2014 IEEE 15TH INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM), 2014,
  • [23] SDN-based Attack Detection in Wireless Local Area Networks
    Cwalinski, Radoslaw
    Koenig, Hartmut
    2018 4TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION AND WORKSHOPS (NETSOFT), 2018, : 207 - 211
  • [24] A SDN-based Deployment Framework for Computer Network Defense Policy
    Gao, Jinghua
    Xia, Chunhe
    Wang, Shuguang
    Zhang, Huajun
    PROCEEDINGS OF 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2015), 2015, : 1253 - 1258
  • [25] A New Framework for DDoS Attack Detection and Defense in SDN Environment
    Tan, Liang
    Pan, Yue
    Wu, Jing
    Zhou, Jianguo
    Jiang, Hao
    Deng, Yuchuan
    IEEE ACCESS, 2020, 8 : 161908 - 161919
  • [26] A Low-Delay SDN-based Countermeasure to Eavesdropping Attacks in Industrial Control Systems
    Ndonda, Gorby Kabasele
    Sadre, Ramin
    2017 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2017, : 135 - 141
  • [27] SDN, A Research on SDN Assets and Tools to Defense DDoS Attack in Cloud Computing Environment
    Tamanna, Tasnim
    Fatema, Tasmiah
    Saha, Reepa
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, SIGNAL PROCESSING AND NETWORKING (WISPNET), 2017, : 1670 - 1674
  • [28] Capitalizing on SDN-Based SCADA Systems: An Anti-Eavesdropping Case-Study
    da Silva, Eduardo Germano
    Dias Knob, Luis Augusto
    Wickboldt, Juliano Araujo
    Gaspary, Luciano Paschoal
    Granville, Lisandro Zambenedetti
    Schaeffer-Filho, Alberto
    PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 165 - 173
  • [29] DDoS Attack Identification and Defense using SDN based on Machine Learning Method
    Yang Lingfeng
    Zhao Hui
    2018 15TH INTERNATIONAL SYMPOSIUM ON PERVASIVE SYSTEMS, ALGORITHMS AND NETWORKS (I-SPAN 2018), 2018, : 166 - 170
  • [30] Control Channel Denial-of-Service Attack in SDN-Based Networks
    Sriskandarajah, Shriparen
    McKague, Matthew
    Foo, Ernest
    Ragel, Roshan G.
    Karunarathna, Suneth Namal
    Jadidi, Zahra
    MERCON 2020: 6TH INTERNATIONAL MULTIDISCIPLINARY MORATUWA ENGINEERING RESEARCH CONFERENCE (MERCON), 2020, : 325 - 330