Heimdallr: Fingerprinting SD-WAN Control-Plane Architecture via Encrypted Control Traffic

被引:4
|
作者
Seo, Minjae [1 ]
Kim, Jaehan [2 ]
Marin, Eduard [3 ]
You, Myoungsung [2 ]
Park, Taejune [4 ]
Lee, Seungsoo [5 ]
Shin, Seungwon [2 ]
Kim, Jinwoo [6 ]
机构
[1] ETRI, Affiliated Inst, Daejeon, South Korea
[2] Korea Adv Inst Sci & Technol, Daejeon, South Korea
[3] Telefon Res, Madrid, Spain
[4] Chonnam Natl Univ, Gwangju, South Korea
[5] Incheon Natl Univ, Incheon, South Korea
[6] Kwangwoon Univ, Seoul, South Korea
基金
新加坡国家研究基金会;
关键词
Software-defined Networking; Fingerprinting; Network Security; NETWORKS; INTERNET;
D O I
10.1145/3564625.3564642
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined wide area network (SD-WAN) has emerged as a new paradigm for steering a large-scale network flexibly by adopting distributed software-defined network (SDN) controllers. The key to building a logically centralized but physically distributed control-plane is running diverse cluster management protocols to achieve consistency through an exchange of control traffic. Meanwhile, we observe that the control traffic exposes unique time-series patterns and directional relationships due to the operational structure even though the traffic is encrypted, and this pattern can disclose confidential information such as control-plane topology and protocol dependencies, which can be exploited for severe attacks. With this insight, we propose a new SD-WAN fingerprinting system, called Heimdallr. It analyzes periodical and operational patterns of SD-WAN cluster management protocols and the context of flow directions from the collected control traffic utilizing a deep learning-based approach, so that it can classify the cluster management protocols automatically from miscellaneous control traffic datasets. Our evaluation, which is performed in a realistic SD-WAN environment consisting of geographically distant three campus networks and one enterprise network shows that Heimdallr can classify SD-WAN control traffic with >= 93%, identify individual protocols with >= 80% macro F-1 scores, and finally can infer control-plane topology with >= 70% similarity.
引用
收藏
页码:949 / 963
页数:15
相关论文
共 11 条
  • [1] Increasing Resilience of SD-WAN by Distributing the Control Plane [Extended Version]
    Altheide, Friedrich
    Buttgereit, Simon
    Rossberg, Michael
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2024, 21 (03): : 2569 - 2581
  • [2] Fingerprinting SDN Applications via Encrypted Control Traffic
    Cao, Jiahao
    Yang, Zijie
    Sun, Kun
    Li, Qi
    Xu, Mingwei
    Han, Peiyi
    PROCEEDINGS OF THE 22ND INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, 2019, : 501 - 515
  • [3] Control-plane Traffic Analysis of UMTS Network
    Zhang, Yi
    Liu, Fang
    Lv, Qiujian
    Wang, Huan
    PROCEEDINGS OF THE FIRST INTERNATIONAL CONFERENCE ON INFORMATION SCIENCES, MACHINERY, MATERIALS AND ENERGY (ICISMME 2015), 2015, 126 : 1019 - 1025
  • [4] A Control-plane Traffic Analysis Tool for LTE Network
    Wang, Jing
    Zhou, Wenli
    Wang, Huan
    Chen, Luying
    2014 SIXTH INTERNATIONAL CONFERENCE ON INTELLIGENT HUMAN-MACHINE SYSTEMS AND CYBERNETICS (IHMSC), VOL 2, 2014, : 218 - 221
  • [5] SD-WAN: how the control of the network can be shifted from core to edge
    Troia, Sebastian
    Zorello, Ligia Maria Moreira
    Maier, Guido
    2021 INTERNATIONAL CONFERENCE ON OPTICAL NETWORK DESIGN AND MODELLING (ONDM), 2021,
  • [6] Control-plane Isolation and Recovery for a Secure SDN Architecture
    Sasaki, Takayuki
    Asoni, Daniele E.
    Perrig, Adrian
    2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 459 - 464
  • [7] Architecture of a Cloud-based Fault-Tolerant Control Platform for improving the QoS of Social Multimedia Applications on SD-WAN
    Basu, Kashinath
    Hamdullah, Aws
    Ball, Frank
    2020 13TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS (COMM), 2020, : 495 - 500
  • [8] A Panoramic View of 3G Data/Control-Plane Traffic: Mobile Device Perspective
    He, Xiuqiang
    Lee, Patrick P. C.
    Pan, Lujia
    He, Cheng
    Lui, John C. S.
    NETWORKING 2012, PT I, 2012, 7289 : 318 - 330
  • [9] Towards Efficient Control Flow Handling in Spatial Architecture via Architecting the Control Flow Plane
    Deng, Jinyi
    Tang, Xinru
    Zhang, Jiahao
    Li, Yuxuan
    Zhang, Linyun
    Han, Boxiao
    He, Hongjun
    Tu, Fengbin
    Liu, Leibo
    Wei, Shaojun
    Hu, Yang
    Yin, Shouyi
    56TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON MICROARCHITECTURE, MICRO 2023, 2023, : 1395 - 1408
  • [10] Optical dynamic Intelligent network services (ODIN): An experimental control-plane architecture for high-performance distributed environments based on dynamic lightpath provisioning
    Mambretti, J
    Lillethun, D
    Lange, J
    Weinberger, J
    IEEE COMMUNICATIONS MAGAZINE, 2006, 44 (03) : 92 - 99