DDoS attacks on data plane of software-defined network: are they possible?

被引:8
|
作者
Wu, Xiaotong [1 ]
Liu, Meng [1 ]
Dou, Wanchun [1 ]
Yu, Shui [2 ]
机构
[1] Nanjing Univ, State Key Lab Novel Software Technol, Nanjing, Jiangsu, Peoples R China
[2] Deakin Univ, Sch Informat Technol, Burwood, Vic 3125, Australia
基金
美国国家科学基金会;
关键词
software-defined network; flooding DDoS; stealthy DDoS; DDoS detection; SECURITY;
D O I
10.1002/sec.1709
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With software-defined networking (SDN) becoming the leading technology for large-scale networks, it is definitely expected that SDN will suffer various types of distributed denial-of-service (DDoS) attacks because of its centralized control logic. However, almost all of existing works concentrate on the controller overloading DDoS attacks, while vulnerabilities exposed by data plane of SDN for DDoS attacks are largely ignored. In this paper, we firstly investigate a flow rule flooding DDoS attack. By thoroughly analyzing the flow table size and miss rate, we find that attackers are able to inflict significant performance degradation over the system with limited volume of attack resource. We then prove that it is possible for attackers to maximize the performance degradation and minimize the attack rate at the same time. Besides the flooding DDoS attack, we also study a novel DDoS attack targeting data plane of SDN. By utilizing the entry lifetime management mechanism of flow tables, this attack almost never exhibits an intensive controller access behavior. It flies under the radar by inflicting non-notable performance impact on the system, while it creates heavy long-term financial burden on the target application. Finally, we present a potential countermeasure for this stealthy DDoS attack. Through extensive experiments, we conclude that DDoS attacks targeting data plane are possible. Copyright (C) 2016 John Wiley & Sons, Ltd.
引用
收藏
页码:5444 / 5459
页数:16
相关论文
共 50 条
  • [41] A Machine Learning Framework for Prevention of Software-Defined Networking controller from DDoS Attacks and dimensionality reduction of big data
    Ali, Jehad
    Roh, Byeong-hee
    Lee, Byungkyu
    Oh, Jimyung
    Adil, Muhammad
    11TH INTERNATIONAL CONFERENCE ON ICT CONVERGENCE: DATA, NETWORK, AND AI IN THE AGE OF UNTACT (ICTC 2020), 2020, : 515 - 519
  • [42] Ensemble Deep Learning Models for Mitigating DDoS Attack in Software-Defined Network
    Alanazi, Fatmah
    Jambi, Kamal
    Eassa, Fathy
    Khemakhem, Maher
    Basuhail, Abdullah
    Alsubhi, Khalid
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2022, 33 (02): : 923 - 938
  • [43] Mitigating DNS Query-Based DDoS Attacks with Machine Learning on Software-Defined Networking
    Ahmed, Muhammad Ejaz
    Kim, Hyoungshick
    Park, Moosung
    MILCOM 2017 - 2017 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2017, : 11 - 16
  • [44] Hybrid Deep Learning Approach for Automatic DoS/DDoS Attacks Detection in Software-Defined Networks
    Elubeyd, Hani
    Yiltas-Kaplan, Derya
    APPLIED SCIENCES-BASEL, 2023, 13 (06):
  • [45] Detection and defense against network isolation attacks in software-defined networks
    Yu, Zhipeng
    Zhu, Hui
    Xiao, Rui
    Song, Chao
    Dong, Jian
    Li, Hui
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2021, 32 (05)
  • [46] Attacking Network Isolation in Software-Defined Networks: New attacks and Countermeasures
    Xiao, Rui
    Zhu, Hui
    Song, Chao
    Liu, Ximeng
    Dong, Jian
    Li, Hui
    2018 27TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN), 2018,
  • [47] Fast Data Plane Testing for Software-Defined Networks With RuleChecker
    Zhang, Peng
    Zhang, Cheng
    Hu, Chengchen
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2019, 27 (01) : 173 - 186
  • [48] Some Controversial Opinions on Software-Defined Data Plane Services
    Risso, Fulvio
    Manzalini, Antonio
    Nemirovsky, Mario
    2013 IEEE WORKSHOP ON SOFTWARE DEFINED NETWORKS FOR FUTURE NETWORKS AND SERVICES (SDN4FNS 2013), 2013,
  • [49] Troubleshooting Data Plane With Rule Verification in Software-Defined Networks
    Zhao, Yusu
    Zhang, Pengfei
    Wang, Yongkun
    Jin, Yaohui
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2018, 15 (01): : 232 - 244
  • [50] A Survey on Data Plane Flexibility and Programmability in Software-Defined Networking
    Kaljic, Enio
    Maric, Almir
    Njemcevic, Pamela
    Hadzialic, Mesud
    IEEE ACCESS, 2019, 7 : 47804 - 47840