Detection and defense against network isolation attacks in software-defined networks

被引:4
|
作者
Yu, Zhipeng [1 ]
Zhu, Hui [1 ]
Xiao, Rui [1 ]
Song, Chao [1 ]
Dong, Jian [1 ]
Li, Hui [1 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Xian 710126, Peoples R China
基金
中国国家自然科学基金;
关键词
MANAGEMENT; IOT; ARCHITECTURE; INTERNET;
D O I
10.1002/ett.3895
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
With the development and pervasiveness of Internet of Things (IoT) devices, Software-Defined Networks (SDN) technology has been deployed to bring great convenience to network transmission. However, SDN over IoT network still faces many challenges on devices data security. Our work demonstrates a novel attack of SDN networks, named Network Harvesting (NH). In NH, an attacker has the ability to steal the users' network privileges without the awareness of victims and the switchers. Furthermore, to solve the above attack, we construct a detection scheme and a defense scheme, named RSDetector and SpoofDefender. RSDetector detects the presence of rogue switches in the network by leveraging the prediction power of machine learning. At the same time, SpoofDefender prevents a number of spoofing attacks including NH by the global control of the SDN networks. In addition, RSDetector and SpoofDefender are also evaluated on ONOS 1.10.4 and Mininet. A good deal of simulation results demonstrate that our proposed schemes have great optimization in reducing communication and computation costs.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Defense Against Software-Defined Network Topology Poisoning Attacks
    Gao, Yang
    Xu, Mingdi
    TSINGHUA SCIENCE AND TECHNOLOGY, 2023, 28 (01): : 39 - 46
  • [2] Attacking Network Isolation in Software-Defined Networks: New attacks and Countermeasures
    Xiao, Rui
    Zhu, Hui
    Song, Chao
    Liu, Ximeng
    Dong, Jian
    Li, Hui
    2018 27TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN), 2018,
  • [3] Distributed Security Network Functions against Botnet Attacks in Software-defined Networks
    Park, Younghee
    Kengalahalli, Nikhil Vijayakumar
    Chang, Sang-Yoon
    2018 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2018,
  • [4] Detection and Prevention of DoS attacks in Software-Defined Cloud Networks
    Rengaraju, Perumalraja
    Ramanan, Raja, V
    Lung, Chung-Horng
    2017 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING, 2017, : 217 - 223
  • [5] Fast Defense System Against Attacks in Software Defined Networks
    De Assis, Marcos V. O.
    Novaes, Matheus P.
    Zerbini, Cinara B.
    Carvalho, Luiz F.
    Abrao, Taufik
    Proenca, Mario L., Jr.
    IEEE ACCESS, 2018, 6 : 69620 - 69639
  • [6] DAISY: A Detection and Mitigation System Against Denial-of-Service Attacks in Software-Defined Networks
    Imran, Muhammad
    Durad, Muhammad Hanif
    Khan, Farrukh Aslam
    Abbas, Haider
    IEEE SYSTEMS JOURNAL, 2020, 14 (02): : 1933 - 1944
  • [7] Poisoning Network Visibility in Software-Defined Networks: New Attacks and Countermeasures
    Hong, Sungmin
    Xu, Lei
    Wang, Haopei
    Gu, Guofei
    22ND ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2015), 2015,
  • [8] Detecting Saturation Attacks in Software-Defined Networks
    Li, Zhiyuan
    Xing, Weijia
    Xu, Dianxiang
    2018 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2018, : 163 - 168
  • [9] Denial of Service Attacks Detection in Software-Defined Wireless Sensor Networks
    Nunez Segura, Gustavo A.
    Skaperas, Sotiris
    Chorti, Arsenia
    Mamatas, Lefteris
    Margi, Cintia Borges
    2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2020,
  • [10] Network fingerprinting via timing attacks and defense in software defined networks
    Yigit, Beytullah
    Gur, Gurkan
    Alagoz, Fatih
    Tellenbach, Bernhard
    COMPUTER NETWORKS, 2023, 232