Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: a comprehensive approach

被引:1
|
作者
Aldaoud, Manar [1 ]
Al-Abri, Dawood [1 ]
Al Maashri, Ahmed [1 ]
Kausar, Firdous [1 ]
机构
[1] Sultan Qaboos Univ, Coll Engn, Dept Elect & Comp Engn, POB 33, Al Khoud 123, Oman
关键词
Software Defined Networking (SDN); OpenFlow; Network Security; Yersinia; DHCP Starvation Attack; DHCP Rouge Server;
D O I
10.1007/s11416-023-00468-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) is an approach that provides centralized control and management of networks. This centralized view of the network traffic flow can be exploited to enhance the network's overall security. This paper focuses on protecting SDN networks from DHCP attacks, which not only impact the DHCP service but also extend to the SDN controller and the overall network. This paper proposes a real-time and comprehensive approach-DHCPWatcher-to detect and mitigate DHCP attacks in SDN networks. The DHCPWatcher is a multi-stage detection mechanism for detecting DHCP attacks using anomaly, heuristic, and/or behavior analysis. When an attack is detected, a DROP action for malicious DHCP traffic is injected into the forwarding device using the OpenFlow protocol. Then, a multi-step mechanism is activated to heal and restore the affected controller and the DHCP service that includes removing spoofed hosts from the controller, releasing IP addresses that may have been maliciously leased by the attack, and reassigning those IP addresses to their original clients. Mininet emulator is utilized to evaluate DHCPWatcher against well-known DHCP attacks for three different DHCP services. The results show that DHCPWatcher effectively detects attacks from the first attack packet. It also can neutralize the impacts of most malicious attacks-Yersinia-within the first 30 s and takes much less time for the other attacks, such as Hyena and DHCPwn. This fast neutralization of attacks positively reflects on the controller resources, such as CPU utilization, and network performance in terms of latency and packet loss.
引用
收藏
页码:597 / 614
页数:18
相关论文
共 50 条
  • [21] Strategies for detecting and mitigating DDoS attacks in SDN: A survey
    Joelle, Misenga Mumpela
    Park, Young-Hoon
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2018, 35 (06) : 5913 - 5925
  • [22] Mitigating Denial of Service (DoS) Attacks in OpenFlow Networks
    Oktian, Yustus Eko
    Lee, SangGon
    Lee, HoonJae
    2014 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC), 2014, : 325 - 330
  • [23] An OpenFlow-based Prototype of SDN-Oriented Stateful Hardware Firewalls
    Collings, Jake
    Liu, Jun
    2014 IEEE 22ND INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2014, : 525 - 528
  • [24] Virtual OpenFlow-based SDN Wi-Fi Access Point
    Stiti, Oussama
    Braham, Othmen
    Pujolle, Guy
    2015 GLOBAL INFORMATION INFRASTRUCTURE AND NETWORKING SYMPOSIUM (GIIS), 2015,
  • [25] Reducing energy consumption in wired OpenFlow-based networks
    Bista, Bhed Bahadur
    Fukushi, Arata
    Takata, Toyoo
    Rawat, Danda B.
    International Journal of Control and Automation, 2014, 7 (06): : 401 - 412
  • [26] Penetrating into Openflow Networks: Novel Ddos Attacks in Sdn and Countermeasures
    Gao, Shang
    Li, Zecheng
    Yao, Yuan
    Xiao, Bin
    SSRN, 2022,
  • [27] OpenFlow-based Mechanisms for QoS in LTE Backhaul Networks
    Chaves, Luciano Jerez
    Garcia, Islene Calciolari
    Mauro Madeira, Edmundo Roberto
    2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 1233 - 1238
  • [28] Cost-effective and accurate flow statistics collection in OpenFlow-based SDN
    Yan, Binghao
    Liu, Qinrang
    Shen, Jianliang
    Liang, Dong
    Liu, Xingyu
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2022, 32 (04)
  • [29] Performance Evaluation of a SDN/OpenFlow-Based Distributed Mobility Management (DMM) Approach in Virtualized LTE Systems
    Valtulina, Luca
    Karimzadeh, Morteza
    Karagiannis, Georgios
    Heijenk, Geert
    Pras, Aiko
    2014 GLOBECOM WORKSHOPS (GC WKSHPS), 2014, : 18 - 23
  • [30] Formal Modeling and Security Analysis for OpenFlow-based Networks
    Zhao, Yongxin
    Wu, Xi
    Liu, Jing
    Yang, Yilong
    2018 23RD INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS (ICECCS), 2018, : 201 - 204