Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: a comprehensive approach

被引:1
|
作者
Aldaoud, Manar [1 ]
Al-Abri, Dawood [1 ]
Al Maashri, Ahmed [1 ]
Kausar, Firdous [1 ]
机构
[1] Sultan Qaboos Univ, Coll Engn, Dept Elect & Comp Engn, POB 33, Al Khoud 123, Oman
关键词
Software Defined Networking (SDN); OpenFlow; Network Security; Yersinia; DHCP Starvation Attack; DHCP Rouge Server;
D O I
10.1007/s11416-023-00468-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) is an approach that provides centralized control and management of networks. This centralized view of the network traffic flow can be exploited to enhance the network's overall security. This paper focuses on protecting SDN networks from DHCP attacks, which not only impact the DHCP service but also extend to the SDN controller and the overall network. This paper proposes a real-time and comprehensive approach-DHCPWatcher-to detect and mitigate DHCP attacks in SDN networks. The DHCPWatcher is a multi-stage detection mechanism for detecting DHCP attacks using anomaly, heuristic, and/or behavior analysis. When an attack is detected, a DROP action for malicious DHCP traffic is injected into the forwarding device using the OpenFlow protocol. Then, a multi-step mechanism is activated to heal and restore the affected controller and the DHCP service that includes removing spoofed hosts from the controller, releasing IP addresses that may have been maliciously leased by the attack, and reassigning those IP addresses to their original clients. Mininet emulator is utilized to evaluate DHCPWatcher against well-known DHCP attacks for three different DHCP services. The results show that DHCPWatcher effectively detects attacks from the first attack packet. It also can neutralize the impacts of most malicious attacks-Yersinia-within the first 30 s and takes much less time for the other attacks, such as Hyena and DHCPwn. This fast neutralization of attacks positively reflects on the controller resources, such as CPU utilization, and network performance in terms of latency and packet loss.
引用
收藏
页码:597 / 614
页数:18
相关论文
共 50 条
  • [41] Performances of OpenFlow-Based Software-Defined Networks: An overview
    Benamrane, Fouad
    Ben Mamoun, Mouad
    Benaini, Redouane
    JOURNAL OF NETWORKS, 2015, 10 (06) : 329 - 337
  • [42] Modeling and Verifying TopoGuard in OpenFlow-Based Software Defined Networks
    Xiang, Shuangqing
    Zhu, Huibiao
    Xiao, Lili
    Xie, Wanling
    PROCEEDINGS 2018 12TH INTERNATIONAL SYMPOSIUM ON THEORETICAL ASPECTS OF SOFTWARE ENGINEERING (TASE 2018), 2018, : 84 - 91
  • [43] Flowlet-level multipath routing based on graph neural network in OpenFlow-based SDN
    Yan, Binghao
    Liu, Qinrang
    Shen, JianLiang
    Liang, Dong
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 134 : 140 - 153
  • [44] OpenFlow-based low-overhead and high-accuracy SDN measurement framework
    He, Qiang
    Wang, Xingwei
    Huang, Min
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2018, 29 (02):
  • [45] OpenFlow-based Flexible Optical Networks with enhanced Monitoring Functionalities
    Paolucci, F.
    Cugini, F.
    Hussain, N.
    Fresi, F.
    Poti, L.
    2012 38TH EUROPEAN CONFERENCE AND EXHIBITION ON OPTICAL COMMUNICATIONS (ECOC), 2012,
  • [46] Woodpecker: Detecting and mitigating link-flooding attacks via SDN
    Wang, Lei
    Li, Qing
    Jiang, Yong
    Jia, Xuya
    Wu, Jianping
    COMPUTER NETWORKS, 2018, 147 : 1 - 13
  • [47] Detecting and Mitigating Target Link-Flooding Attacks Using SDN
    Wang, Juan
    Wen, Ru
    Li, Jiangqi
    Yan, Fei
    Zhao, Bo
    Yu, Fajiang
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (06) : 944 - 956
  • [48] An Openflow-Based Approach to Failure Detection and Protection for a Multicasting Tree
    Raja, Vignesh Renganathan
    Pandey, Abhishek
    Lung, Chung-Horng
    WIRED/WIRELESS INTERNET COMMUNICATIONS, WWIC 2015, 2015, 9071 : 211 - 224
  • [49] An OpenFlow-Based Energy-Efficient Data Center Approach
    Jarschel, Michael
    Pries, Rastin
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2012, 42 (04) : 87 - 88
  • [50] OpenFlow-Based Dynamic Traffic Distribution in Software-Defined Networks
    Chaulagain, Duryodhan
    Pudashine, Kumar
    Paudyal, Rajendra
    Mishra, Sagar
    Shakya, Subarna
    MOBILE COMPUTING AND SUSTAINABLE INFORMATICS, 2022, 68 : 259 - 272