Hop-by-Hop Verification Mechanism of Packet Forwarding Path Oriented to Programmable Data Plane

被引:1
|
作者
Zeng, Junsan [1 ]
Liu, Ying [1 ]
Zhang, Weiting [1 ]
Yan, Xincheng [2 ,3 ]
Zhou, Na [2 ,3 ]
Jiang, Zhihong [2 ,3 ]
机构
[1] Beijing Jiaotong Univ, Natl Engn Res Ctr Adv Network Technol, Beijing, Peoples R China
[2] State Key Lab Mobile Network & Mobile Multimedia, Shenzhen 518055, Peoples R China
[3] ZTE Corp, Nanjing 210012, Peoples R China
关键词
Path verification; SDN; P4; INT; NETWORKS;
D O I
10.1007/978-981-19-9697-9_37
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Attacks against the forwarding path could deviate data packets from the predefined route to achieve ulterior purposes, which has posed a serious threat to the software-defined network. Previous studies attempted to solve this security issue through complex authentication or traffic statistics methods. However, existing schemes have the disadvantages of high bandwidth overhead and high process delay. Hence, this article proposed a lightweight forwarding path verification mechanism based on P4 implementation. First, we deployed inband network telemetry to obtain path information, and then performed the path verification inside each hop in the programmable data plane to ensure that various attacks against forwarding paths could be intercepted. Finally, complete path verification information would convey to the control plane for backup. Corresponding experimental results demonstrate that our mechanism can effectively improve the security of the packet forwarding path with acceptable throughput and delay.
引用
收藏
页码:454 / 466
页数:13
相关论文
共 50 条
  • [1] Void hole avoidance using three hop-by-hop forwarding verification in UWSN
    Hussain, Altaf
    Hussain, Tariq
    Ali, Farman
    Attar, Razaz Waheeb
    Alhomoud, Ahmed
    TELECOMMUNICATION SYSTEMS, 2025, 88 (01)
  • [2] Hop-by-hop Accounting and Rewards for Packet dIspAtching
    Machado, Caciano
    dos Santos, Renan R. S.
    Westphall, Carla Merkle
    2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 1116 - 1123
  • [3] A hop-by-hop flow controller for a virtual path
    Zhang, HY
    Yang, OW
    Mouftah, H
    COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 2000, 32 (01): : 99 - 119
  • [4] A Software-Defined Networking Packet Forwarding Verification Mechanism Based on Programmable Data Plane
    Zuo Zhibin
    Chang Chaowen
    Zhu Xianwei
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2020, 42 (05) : 1110 - 1117
  • [5] Multipath policy routing using destination based hop-by-hop forwarding
    Amaral, Pedro
    Bernardo, Luis
    Pinto, Paulo
    2013 21ST IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2013,
  • [6] A Hop-by-Hop Routing Mechanism for Green Internet
    Yang, Yuan
    Xu, Mingwei
    Wang, Dan
    Li, Suogang
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2016, 27 (01) : 2 - 16
  • [7] Achieving Correct Hop-by-Hop Forwarding on Multiple Policy-Based Routing Paths
    Amaral, Pedro
    Pinto, Paulo
    Bernardo, Luis
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2020, 7 (03): : 1226 - 1238
  • [8] Hop-By-Hop Congestion Control for Named Data Networks
    Mejri, Safa
    Touati, Haifa
    Malouch, Naceur
    Kamoun, Farouk
    2017 IEEE/ACS 14TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2017, : 114 - 119
  • [9] A Lightweight Authentication and Hop-by-Hop Security Mechanism for SIP Network
    Choi, Jueduck
    Jung, Souhwan
    Bac, Kwangyong
    Moon, Hokun
    2008 INTERNATIONAL CONFERENCE ON ADVANCED TECHNOLOGIES FOR COMMUNICATIONS, PROCEEDINGS, 2008, : 239 - 242
  • [10] Algebra and algorithms for QoS path computation and hop-by-hop routing in the Internet
    Sobrinho, JL
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2002, 10 (04) : 541 - 550