A proactive defense method against eavesdropping attack in SDN-based storage environment

被引:0
|
作者
Liu, Yuming [1 ]
Wang, Yong [1 ]
Feng, Hao [1 ]
机构
[1] Guilin Univ Elect Technol, Sch Comp & Informat Secur, Guilin 541004, Peoples R China
来源
CYBERSECURITY | 2024年 / 7卷 / 01期
基金
中国国家自然科学基金;
关键词
SDN; Storage center; Eavesdropping attack; Moving target defense; End hopping; ROUTE MUTATION; NETWORK; MECHANISM; FLOW;
D O I
10.1186/s42400-024-00255-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The integration of Software-Defined Networking (SDN) in storage centers aims to enhance storage performance. However, this integration also introduces new concerns, particularly the potential eavesdropping attacks that pose a substantial risk to data privacy. By issuing flow tables (e.g., via compromised SDN switches), attackers can conveniently collect target traffic and extract confidential information with session reassembly methods. To proactively mitigate such attacks by preventing session reassembly, various moving target defense methods, such as end hopping, have been proposed. However, this study uncovers several deficiencies within existing end hopping methods. To address these deficiencies, we propose a novel linkage-field-based self-synchronizing end hopping method, which obfuscates end information (e.g., IP, Port) and linkage fields (e.g., sequence number and ID number) without third-party assistance. Furthermore, to counter the potential invalidation of end hopping methods resulting from brute-force reassembly of a small number of sessions, we propose a fake segment injection method. Extensive experiments have been conducted both in simulation and real-world environment to evaluate the effectiveness of our proposed methods. The results demonstrate that our proposed methods can effectively defend against eavesdropping attacks with acceptable performance overhead.
引用
收藏
页数:19
相关论文
共 50 条
  • [31] XGBoost Classifier for DDoS Attack Detection and Analysis in SDN-based Cloud
    Chen, Zhuo
    Jiang, Fu
    Cheng, Yijun
    Gu, Xin
    Liu, Weirong
    Peng, Jun
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA AND SMART COMPUTING (BIGCOMP), 2018, : 251 - 256
  • [32] Periodic Subflow-based Proactive Flow Installation Mechanism in SDN-based IoT
    Cai, Yun-Zhan
    Tien, Shao-Ku
    Wang, Yu-Ting
    Tsai, Meng-Hsun
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [33] Hierarchical OAM Infrastructure for Proactive Control of SDN-based Elastic Optical Networks
    Paolucci, Francesco
    Sgambelluri, Andrea
    Sambo, Nicola
    Cugini, Filippo
    Castoldi, Piero
    2015 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2015,
  • [34] Proactive Admission Control and Dynamic Resource Management in SDN-based Virtualized Networks
    Shakeri, Sara
    Parsaeefard, Saeedeh
    Derakhshani, Mahsa
    PROCEEDINGS OF THE 2017 8TH INTERNATIONAL CONFERENCE ON THE NETWORK OF THE FUTURE (NOF), 2017, : 46 - 51
  • [35] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [36] An SDN-Based Moving Target Defense as a Countermeasure to Prevent Network Scans
    Chiba, Shoya
    Guillen, Luis
    Izumi, Satoru
    Abe, Toru
    Suganuma, Takuo
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2022, E105B (11) : 1400 - 1407
  • [37] CyberShip: An SDN-Based Autonomic Attack Mitigation Framework for Ship Systems
    Sahay, Rishikesh
    Sepulveda, D. A.
    Meng, Weizhi
    Jensen, Christian Damsgaard
    Barfod, Michael Bruhn
    SCIENCE OF CYBER SECURITY, SCISEC 2018, 2018, 11287 : 191 - 198
  • [38] SDN-based Network Security Functions for Effective DDoS Attack Mitigation
    Hyun, Daeyoung
    Kim, Jinyoug
    Hong, Dongjin
    Jeong, Jaehoon
    2017 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC), 2017, : 834 - 839
  • [39] Towards a SDN-Based Integrated Architecture for Mitigating IP Spoofing Attack
    Zhang, Chaoqin
    Hu, Guangwu
    Chen, Guolong
    Sangaiah, Arun Kumar
    Zhang, Ping'an
    Yan, Xia
    Jiang, Weijin
    IEEE ACCESS, 2018, 6 : 22764 - 22777
  • [40] Mitigating Crossfire Attacks using SDN-based Moving Target Defense
    Aydeger, Abdullah
    Saputro, Nico
    Akkaya, Kemal
    Rahman, Mohammad
    2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 627 - 630