Constant-Size Credential-Based Packet Forwarding Verification in SDN

被引:1
|
作者
Wu, Ping [1 ,2 ]
Chang, Chao-Wen [1 ,2 ]
Ma, Ying-Ying [1 ,2 ]
Zuo, Zhi-Bin [3 ]
机构
[1] Zhengzhou Informat Sci & Technol Inst, Zhengzhou 450001, Henan, Peoples R China
[2] Henan Key Lab Informat Secur, Zhengzhou 450001, Henan, Peoples R China
[3] Henan Univ Technol, Zhengzhou 450001, Henan, Peoples R China
基金
中国国家自然科学基金;
关键词
Compendex;
D O I
10.1155/2022/2270627
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emerging software-defined networking (SDN) technology lacks tools to proactively ensure that policies will be followed or to inspect the behavior of the network. The network is vulnerable to sophisticated attacks against packets, such as alteration, injection, dropping, and hijacking attacks. Accurate and efficient network packet forwarding verification is a critical issue to ensure the correctness of packet forwarding when confronting with malicious attacks, while most of the existing packet forwarding verification solutions were implemented by inserting linear-scale cryptographic tags that increased with path length, which introduced significant communication overhead. In this paper, we propose a constant-size credential based packet forwarding verification mechanism in SDN. In the scheme, the ingress switch of a flow embeds a tag credential of constant-size which is independent of the packet forwarding path, each downstream switch verifies packets basing on the constant-size credential, and the controller periodically acquires node forwarding statistics along the path and localizes anomaly. The header space communication overhead of the proposed scheme is less than existing linear-scale mechanisms. We further prototype and evaluate the proposed scheme. Experiments demonstrate that the scheme achieves efficient forwarding and effective anomaly localization with less than 11% of additional forwarding delays and no more than 10% of throughput degradation.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] Dynamic Packet Forwarding Verification in SDN
    Li, Qi
    Zou, Xiaoyue
    Huang, Qun
    Zheng, Jing
    Lee, Patrick P. C.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (06) : 915 - 929
  • [2] Port address overloading based packet forwarding verification in SDN
    Wu P.
    Chang C.
    Ma Y.
    Tongxin Xuebao/Journal on Communications, 2021, 42 (07): : 70 - 83
  • [3] Address overloading-based packet forwarding verification in SDN
    Wu P.
    Chang C.
    Zuo Z.
    Ma Y.
    Tongxin Xuebao/Journal on Communications, 2022, 43 (03): : 88 - 100
  • [4] LPV: Lightweight Packet Forwarding Verification in SDN
    Wang S.-Y.
    Li Q.
    Zhang Y.
    Jisuanji Xuebao/Chinese Journal of Computers, 2019, 42 (01): : 176 - 189
  • [5] A lightweight packet forwarding verification in SDN using sketch
    Chang, Heyu
    Zhang, Xiaobing
    Si, Nianwen
    Wu, Ping
    COMPUTERS & SECURITY, 2024, 144
  • [6] An Anonymous Credential System with Constant-Size Attribute Proofs for CNF Formulas with Negations
    Okishima, Ryo
    Nakanishi, Toru
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2019, 2019, 11689 : 89 - 106
  • [7] An Anonymous Credential System with Constant-Size Attribute Proofs for CNF Formulas with Negations
    Okishima, Ryo
    Nakanishi, Toru
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2020, E103A (12) : 1381 - 1392
  • [8] Anonymous Credential-Based Privacy-Preserving Identity Verification for Business Processes
    Guo, Nan
    Jin, Yuanting
    Yim, Kangbin
    2014 Eighth International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2014, : 554 - 559
  • [9] GwPFV: A novel packet forwarding verification mechanism based on gateways in SDN-based storage environment
    Yuming, Liu
    Yong, Wang
    Hao, Feng
    Zeyu, Wang
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 71
  • [10] An Efficiency Improvement in an Anonymous Credential System for CNF Formulas on Attributes with Constant-size Proofs
    Begum, Nasima
    Nakanishi, Toru
    Nogami, Yasuyuki
    2ND INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING AND INFORMATION COMMUNICATION TECHNOLOGY (ICEEICT 2015), 2015,