Misreporting Attacks in Software-Defined Networking

被引:2
|
作者
Burke, Quinn [1 ]
McDaniel, Patrick [1 ]
La Porta, Thomas [1 ]
Yu, Mingli [1 ]
He, Ting [1 ]
机构
[1] Penn State Univ, State Coll, PA 16801 USA
基金
美国国家科学基金会;
关键词
Network security; SDN; Load balancing;
D O I
10.1007/978-3-030-63086-7_16
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Load balancers enable efficient use of network resources by distributing traffic fairly across them. In software-defined networking (SDN), load balancing is most often realized by a controller application that solicits traffic load reports from network switches and enforces load balancing decisions through flow rules. This separation between the control and data planes in SDNs creates an opportunity for an adversary at a compromised switch to misreport traffic loads to influence load balancing. In this paper, we evaluate the ability of such an adversary to control the volume of traffic flowing through a compromised switch by misreporting traffic loads. We use a queuing theoretic approach to model the attack and develop algorithms for misreporting that allow an adversary to tune attack parameters toward specific adversarial goals. We validate the algorithms with a virtual network testbed, finding that through misreporting the adversary can draw nearly all of the load in the subnetwork (+750%, or 85% of the load in the system), or an adversary-desired amount of load (a target load, e.g., +200%) to within 12% error of that target. This is yet another example of how depending on untrustworthy reporting in making control decisions can lead to fundamental security failures.
引用
收藏
页码:276 / 296
页数:21
相关论文
共 50 条
  • [21] A Survey of Multicast in Software-Defined Networking
    Gu, Weidong
    Zhang, Xinchang
    Gong, Bin
    Wang, Lu
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION ENGINEERING FOR MECHANICS AND MATERIALS, 2015, 21 : 1096 - 1100
  • [22] Software-Defined Networking: On the Verge of a Breakthrough?
    Ortiz, Sixto, Jr.
    COMPUTER, 2013, 46 (07) : 10 - 12
  • [23] Verification Framework for Software-Defined Networking
    Kang, Miyoung
    Cho, Jong Jin
    2022 24TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ARITIFLCIAL INTELLIGENCE TECHNOLOGIES TOWARD CYBERSECURITY, 2022, : 518 - 523
  • [24] A Survey on Multicasting in Software-Defined Networking
    Islam, Salekul
    Muslim, Nasif
    Atwood, J. William
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (01): : 355 - 387
  • [25] Toward Software-Defined Middlebox Networking
    Gember, Aaron
    Prabhu, Prathmesh
    Ghadiyali, Zainab
    Akella, Aditya
    PROCEEDINGS OF THE 11TH ACM WORKSHOP ON HOT TOPICS IN NETWORKS (HOTNETS-XI), 2012, : 7 - 12
  • [26] Software-defined networking (SDN): a survey
    Benzekki, Kamal
    El Fergougui, Abdeslam
    Elalaoui, Abdelbaki Elbelrhiti
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) : 5803 - 5833
  • [27] Toward Software-Defined Battlefield Networking
    Nobre, Jeferson
    Rosario, Denis
    Both, Cristiano
    Cerqueira, Eduardo
    Gerla, Mario
    IEEE COMMUNICATIONS MAGAZINE, 2016, 54 (10) : 152 - 157
  • [28] Semantic Failover in Software-Defined Networking
    Hsueh, Shu-Wen
    Lin, Tung-Yueh
    Lei, Weng-Ian
    Ngai, Chi-Leung Patrick
    Sheng, Yu-Hang
    Wu, Yu-Sung
    2018 IEEE 23RD PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC), 2018, : 299 - 308
  • [29] A Software-Defined Approach to IoT Networking
    Christian Jacquenet
    Mohamed Boucadair
    ZTE Communications, 2016, 14 (01) : 61 - 66
  • [30] Software-Defined Networking of Linux Containers
    Costache, Cosmin
    Machidon, Octavian
    Mladin, Adrian
    Sandu, Florin
    Bocu, Razvan
    2014 ROEDUNET CONFERENCE 13TH EDITION: NETWORKING IN EDUCATION AND RESEARCH JOINT EVENT RENAM 8TH CONFERENCE, 2014,