rDefender: A Lightweight and Robust Defense Against Flow Table Overflow Attacks in SDN

被引:1
|
作者
Kong, Dezhang [1 ,2 ]
Chen, Xiang [1 ,2 ]
Wu, Chunming [1 ,2 ]
Shen, Yi [1 ]
Zhou, Zhengyan [1 ,2 ]
Cheng, Qiumei [1 ]
Liu, Xuan [3 ]
Yang, Mingliang [4 ]
Qiu, Yubing [4 ]
Zhang, Dong [5 ]
Khan, Muhammad Khurram [6 ]
机构
[1] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310058, Peoples R China
[2] Quan Cheng Lab, Jinan 250103, Peoples R China
[3] Yangzhou Univ, Coll Informat Engn, Coll Artificial Intelligence, Yangzhou 225009, Peoples R China
[4] Alibaba Cloud, Hangzhou 311121, Peoples R China
[5] Fuzhou Univ, Coll Comp & Data Sci, Fuzhou 350002, Peoples R China
[6] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh 11421, Saudi Arabia
基金
中国国家自然科学基金;
关键词
Software-defined networking; table overflow attacks; security; RATE DDOS ATTACK;
D O I
10.1109/TIFS.2024.3472477
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The flow table is a critical component of Software-Defined Networking (SDN). However, flow tables' limited capacity makes them highly vulnerable to flow table overflow attacks (FTOAs). Due to the low attack cost and highly flexible attack forms, it is hard to eradicate FTOAs. This paper addresses three unsolved problems for table security and proposes a robust defense accordingly. First, we reveal that the existing defenses with fixed defense speeds will cause severe packet loss when handling diverse traffic. We prove that deleting multiple rules can efficiently solve this problem and give a rigorous derivation to calculate the suitable deletion number according to the environment. Second, we illustrate that abnormal table occupancy squeezing is a constant characteristic of FTOAs regardless of attack forms. It can be used to identify attacked ports accurately in different scenarios. Third, we mathematically prove that random deletion can guarantee the continuous decrease of malicious flow rules after confirming attacked ports. It achieves fast speed and robust effectiveness in different environments. Based on these findings, we design rDefender, a robust and lightweight defense prototype. We evaluate its effect by designing diverse, powerful attacks and using real-world datasets and topology. The results demonstrate that it achieves the best overall performance compared to six existing mainstream defenses, providing stable security for switch flow tables.
引用
收藏
页码:9436 / 9451
页数:16
相关论文
共 50 条
  • [21] Flow Table Security in SDN: Adversarial Reconnaissance and Intelligent Attacks
    Yu, Mingli
    He, Ting
    McDaniel, Patrick
    Burke, Quinn K.
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2021, 29 (06) : 2793 - 2806
  • [22] Flow Table Security in SDN: Adversarial Reconnaissance and Intelligent Attacks
    Yu, Mingli
    He, Ting
    McDaniel, Patrick
    Burke, Quinn K.
    IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, 2020, : 1519 - 1528
  • [23] Unmasking SDN flow table saturation: fingerprinting, attacks and defenses
    Yigit, Beytullah
    Gur, Gurkan
    Tellenbach, Bernhard
    Alagoz, Fatih
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (06) : 3465 - 3479
  • [24] FloRa: Flow Table Low-Rate Overflow Reconnaissance and Detection in SDN
    Mudgal, Ankur
    Verma, Abhishek
    Singh, Munesh
    Sahoo, Kshira Sagar
    Elmroth, Erik
    Bhuyan, Monowar
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2024, 21 (06): : 6670 - 6683
  • [25] A binary rewriting defense against stack based buffer overflow attacks
    Prasad, M
    Chiueh, TC
    USENIX ASSOCIATION PROCEEDINGS OF THE GENERAL TRACK, 2003, : 211 - 224
  • [26] Embedded TaintTracker: Lightweight Tracking of Taint Data against Buffer Overflow Attacks
    Lin, Ying-Dar
    Wu, Fan-Cheng
    Huang, Tze-Yau
    Lai, Yuan-Cheng
    Lin, Frank C.
    2010 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2010,
  • [27] On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN
    Wu, Hao
    Hou, Aiqin
    Nie, Weike
    Wu, Chase
    2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 311 - 317
  • [28] SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    2017 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2017, : 669 - 675
  • [29] A Lightweight Compound Defense Framework Against Injection Attacks in IIoT
    Chi, Po-Wen
    Wang, Ming-Hung
    2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2018, : 30 - 37
  • [30] FLIP the (Flow) Table: Fast LIghtweight Policy-preserving SDN Updates
    Vissicchio, Stefano
    Cittadini, Luca
    IEEE INFOCOM 2016 - THE 35TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS, 2016,