Detection and defense against network isolation attacks in software-defined networks

被引:4
|
作者
Yu, Zhipeng [1 ]
Zhu, Hui [1 ]
Xiao, Rui [1 ]
Song, Chao [1 ]
Dong, Jian [1 ]
Li, Hui [1 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Xian 710126, Peoples R China
基金
中国国家自然科学基金;
关键词
MANAGEMENT; IOT; ARCHITECTURE; INTERNET;
D O I
10.1002/ett.3895
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
With the development and pervasiveness of Internet of Things (IoT) devices, Software-Defined Networks (SDN) technology has been deployed to bring great convenience to network transmission. However, SDN over IoT network still faces many challenges on devices data security. Our work demonstrates a novel attack of SDN networks, named Network Harvesting (NH). In NH, an attacker has the ability to steal the users' network privileges without the awareness of victims and the switchers. Furthermore, to solve the above attack, we construct a detection scheme and a defense scheme, named RSDetector and SpoofDefender. RSDetector detects the presence of rogue switches in the network by leveraging the prediction power of machine learning. At the same time, SpoofDefender prevents a number of spoofing attacks including NH by the global control of the SDN networks. In addition, RSDetector and SpoofDefender are also evaluated on ONOS 1.10.4 and Mininet. A good deal of simulation results demonstrate that our proposed schemes have great optimization in reducing communication and computation costs.
引用
收藏
页数:16
相关论文
共 50 条
  • [31] BuDDI: Bug Detection, Debugging, and Isolation Middlebox for Software-Defined Network Controllers
    Abhishek, Rohit
    Zhao, Shuai
    Song, Sejun
    Choi, Baek-Young
    Zhu, Henry
    Medhi, Deep
    2016 12TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT AND WORKSHOPS(CNSM 2016), 2016, : 307 - 311
  • [32] Misreporting Attacks Against Load Balancers in Software-Defined Networking
    Burke, Quinn
    McDaniel, Patrick
    La Porta, Thomas
    Yu, Mingli
    He, Ting
    MOBILE NETWORKS & APPLICATIONS, 2023, 28 (04): : 1482 - 1497
  • [33] Collaborative Detection and Mitigation of Distributed Denial-of-Service Attacks on Software-Defined Network
    Omer Elsier Tayfour
    Muhammad Nadzir Marsono
    Mobile Networks and Applications, 2020, 25 : 1338 - 1347
  • [34] Federated Learning Based DDoS Attacks Detection in Large Scale Software-Defined Network
    Fotse, Yannis Steve Nsuloun
    Tchendji, Vianney Kengne
    Velempini, Mthulisi
    IEEE TRANSACTIONS ON COMPUTERS, 2025, 74 (01) : 101 - 115
  • [35] Collaborative Detection and Mitigation of Distributed Denial-of-Service Attacks on Software-Defined Network
    Tayfour, Omer Elsier
    Marsono, Muhammad Nadzir
    MOBILE NETWORKS & APPLICATIONS, 2020, 25 (04): : 1338 - 1347
  • [36] Software defined network moving target defense mechanism against link flooding attacks
    Xie L.
    Ding Y.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (01): : 36 - 43
  • [37] Effective Topology Tampering Attacks and Defenses in Software-Defined Networks
    Skowyra, Richard
    Xu, Lei
    Gu, Guofei
    Dedhia, Veer
    Hobson, Thomas
    Okhravi, Hamed
    Landry, James
    2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2018, : 374 - 385
  • [38] Topology Poisoning Attacks and Prevention in Hybrid Software-Defined Networks
    Shrivastava, Pragati
    Kataoka, Kotaro
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (01): : 510 - 523
  • [39] A Testbed for the Evaluation of Denial of Service Attacks in Software-Defined Networks
    Wright, Andrea P.
    Ghani, Nasir
    2019 IEEE SOUTHEASTCON, 2019,
  • [40] Control Plane Reflection Attacks and Defenses in Software-Defined Networks
    Zhang, Menghao
    Li, Guanyu
    Xu, Lei
    Bai, Jiasong
    Xu, Mingwei
    Gu, Guofei
    Wu, Jianping
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2021, 29 (02) : 623 - 636