Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: a comprehensive approach

被引:1
|
作者
Aldaoud, Manar [1 ]
Al-Abri, Dawood [1 ]
Al Maashri, Ahmed [1 ]
Kausar, Firdous [1 ]
机构
[1] Sultan Qaboos Univ, Coll Engn, Dept Elect & Comp Engn, POB 33, Al Khoud 123, Oman
关键词
Software Defined Networking (SDN); OpenFlow; Network Security; Yersinia; DHCP Starvation Attack; DHCP Rouge Server;
D O I
10.1007/s11416-023-00468-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) is an approach that provides centralized control and management of networks. This centralized view of the network traffic flow can be exploited to enhance the network's overall security. This paper focuses on protecting SDN networks from DHCP attacks, which not only impact the DHCP service but also extend to the SDN controller and the overall network. This paper proposes a real-time and comprehensive approach-DHCPWatcher-to detect and mitigate DHCP attacks in SDN networks. The DHCPWatcher is a multi-stage detection mechanism for detecting DHCP attacks using anomaly, heuristic, and/or behavior analysis. When an attack is detected, a DROP action for malicious DHCP traffic is injected into the forwarding device using the OpenFlow protocol. Then, a multi-step mechanism is activated to heal and restore the affected controller and the DHCP service that includes removing spoofed hosts from the controller, releasing IP addresses that may have been maliciously leased by the attack, and reassigning those IP addresses to their original clients. Mininet emulator is utilized to evaluate DHCPWatcher against well-known DHCP attacks for three different DHCP services. The results show that DHCPWatcher effectively detects attacks from the first attack packet. It also can neutralize the impacts of most malicious attacks-Yersinia-within the first 30 s and takes much less time for the other attacks, such as Hyena and DHCPwn. This fast neutralization of attacks positively reflects on the controller resources, such as CPU utilization, and network performance in terms of latency and packet loss.
引用
收藏
页码:597 / 614
页数:18
相关论文
共 50 条
  • [31] Detecting host location attacks in SDN-based networks
    Sen Baidya, Sonali
    Hewett, Rattikorn
    2020 29TH WIRELESS AND OPTICAL COMMUNICATIONS CONFERENCE (WOCC), 2020, : 80 - 85
  • [32] Generalizing virtual network topologies in OpenFlow-based networks
    Salvadori, Elio
    Corin, Roberto Doriguzzi
    Broglio, Attilio
    Gerola, Matteo
    2011 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE (GLOBECOM 2011), 2011,
  • [33] Detection and defense of DDoS attack-based on deep learning in OpenFlow-based SDN
    Li, Chuanhuang
    Wu, Yan
    Yuan, Xiaoyong
    Sun, Zhengjun
    Wang, Weiming
    Li, Xiaolin
    Gong, Liang
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2018, 31 (05)
  • [34] Making Queueing Theory More Palatable to SDN/OpenFlow-based Network Practitioners
    Ansell, Jordan
    Seah, Winston K. G.
    Ng, Bryan
    Marshall, Stuart
    NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 1119 - 1124
  • [35] SDN-based Edge Computing Security: Detecting and Mitigating Flow Rule Attacks
    Sen Baidya, Sonali
    Hewett, Rattikorn
    SEC'19: PROCEEDINGS OF THE 4TH ACM/IEEE SYMPOSIUM ON EDGE COMPUTING, 2019, : 364 - 370
  • [36] Independent Transient Plane Design for Protection in OpenFlow-Based Networks
    Kitsuwan, Nattapong
    McGettrick, Seamas
    Slyne, Frank
    Payne, David B.
    Ruffini, Marco
    JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2015, 7 (04) : 264 - 275
  • [37] Architecture on Mobility Management in OpenFlow-based Radio Access Networks
    Sun, Guolin
    Liu, Guisong
    Zhang, Hangming
    Tan, Wei
    2013 IEEE GLOBAL HIGH TECH CONGRESS ON ELECTRONICS (GHTCE), 2013,
  • [38] Efficient topology discovery in OpenFlow-based Software Defined Networks
    Pakzad, Farzaneh
    Portmann, Marius
    Tan, Wee Lum
    Indulska, Jadwiga
    COMPUTER COMMUNICATIONS, 2016, 77 : 52 - 61
  • [39] OpenFlow-Based Control Architecture for the Mobile FreeSpace Optical Networks
    Zhao Yongli
    Gao Lingnan
    Yin Xingbin
    Yu Yue
    Zhang Jie
    CHINA COMMUNICATIONS, 2014, 11 (08) : 65 - 72
  • [40] Periodic Control Update Overheads in OpenFlow-Based Enterprise Networks
    Awobuluyi, Olatunde
    2014 IEEE 28TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2014, : 390 - 396