DDoS attacks on data plane of software-defined network: are they possible?

被引:8
|
作者
Wu, Xiaotong [1 ]
Liu, Meng [1 ]
Dou, Wanchun [1 ]
Yu, Shui [2 ]
机构
[1] Nanjing Univ, State Key Lab Novel Software Technol, Nanjing, Jiangsu, Peoples R China
[2] Deakin Univ, Sch Informat Technol, Burwood, Vic 3125, Australia
基金
美国国家科学基金会;
关键词
software-defined network; flooding DDoS; stealthy DDoS; DDoS detection; SECURITY;
D O I
10.1002/sec.1709
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With software-defined networking (SDN) becoming the leading technology for large-scale networks, it is definitely expected that SDN will suffer various types of distributed denial-of-service (DDoS) attacks because of its centralized control logic. However, almost all of existing works concentrate on the controller overloading DDoS attacks, while vulnerabilities exposed by data plane of SDN for DDoS attacks are largely ignored. In this paper, we firstly investigate a flow rule flooding DDoS attack. By thoroughly analyzing the flow table size and miss rate, we find that attackers are able to inflict significant performance degradation over the system with limited volume of attack resource. We then prove that it is possible for attackers to maximize the performance degradation and minimize the attack rate at the same time. Besides the flooding DDoS attack, we also study a novel DDoS attack targeting data plane of SDN. By utilizing the entry lifetime management mechanism of flow tables, this attack almost never exhibits an intensive controller access behavior. It flies under the radar by inflicting non-notable performance impact on the system, while it creates heavy long-term financial burden on the target application. Finally, we present a potential countermeasure for this stealthy DDoS attack. Through extensive experiments, we conclude that DDoS attacks targeting data plane are possible. Copyright (C) 2016 John Wiley & Sons, Ltd.
引用
收藏
页码:5444 / 5459
页数:16
相关论文
共 50 条
  • [21] Machine learning assisted snort and zeek in detecting DDoS attacks in software-defined networking
    AbdulRaheem M.
    Oladipo I.D.
    Imoize A.L.
    Awotunde J.B.
    Lee C.-C.
    Balogun G.B.
    Adeoti J.O.
    International Journal of Information Technology, 2024, 16 (3) : 1627 - 1643
  • [22] An Efficient Scheme to Defend Data-to-Control-Plane Saturation Attacks in Software-Defined Networking
    Xuan-Bo Huang
    Kai-Ping Xue
    Yi-Tao Xing
    Ding-Wen Hu
    Ruidong Li
    Qi-Bin Sun
    Journal of Computer Science and Technology, 2022, 37 : 839 - 851
  • [23] An Efficient Scheme to Defend Data-to-Control-Plane Saturation Attacks in Software-Defined Networking
    Huang, Xuan-Bo
    Xue, Kai-Ping
    Xing, Yi-Tao
    Hu, Ding-Wen
    Li, Ruidong
    Sun, Qi-Bin
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2022, 37 (04) : 839 - 851
  • [24] The forensics of ddos attacks in the fifth generation mobile networks based on software-defined networks
    Sedaghat, Shahrzad
    Sedaghat, Shahrzad (shsedaghat@jahromu.ac.ir), 1600, Femto Technique Co., Ltd. (22): : 41 - 53
  • [25] A Novel Hybrid Flow-based Handler with DDoS Attacks in Software-Defined Networking
    Phan, Trung V.
    Nguyen Khac Bao
    Park, Minho
    2016 INT IEEE CONFERENCES ON UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING AND COMMUNICATIONS, CLOUD AND BIG DATA COMPUTING, INTERNET OF PEOPLE, AND SMART WORLD CONGRESS (UIC/ATC/SCALCOM/CBDCOM/IOP/SMARTWORLD), 2016, : 350 - 357
  • [26] Investigation of application layer DDoS attacks in legacy and software-defined networks: A comprehensive review
    Kaur, Sarabjeet
    Sandhu, Amanpreet Kaur
    Bhandari, Abhinav
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (06) : 1949 - 1988
  • [27] Investigation of application layer DDoS attacks in legacy and software-defined networks: A comprehensive review
    Sarabjeet Kaur
    Amanpreet Kaur Sandhu
    Abhinav Bhandari
    International Journal of Information Security, 2023, 22 : 1949 - 1988
  • [28] LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined Networking
    Ambrosin, Moreno
    Conti, Mauro
    De Gaspari, Fabio
    Poovendran, Radha
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (02) : 1206 - 1219
  • [29] Security Threats in the Data Plane of Software-Defined Networks
    Gao, Shang
    Li, Zecheng
    Xiao, Bin
    Wei, Guiyi
    IEEE NETWORK, 2018, 32 (04): : 108 - 113
  • [30] DDoS protection with stateful software-defined networking
    Rebecchi, Filippo
    Boite, Julien
    Nardin, Pierre-Alexis
    Bouet, Mathieu
    Conan, Vania
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2019, 29 (01)