Disrupting SDN via the Data Plane: A Low-Rate Flow Table Overflow Attack

Disrupting SDN via the Data Plane: A Low-Rate Flow Table Overflow Attack
复制标题

DOI:
10.1007/978-3-319-78813-5_18
复制
发表时间:
2017-10
期刊:
--
影响因子:
--
通讯作者:
Jiahao Cao;Mingwei Xu;Qi Li;Kun Sun;Yuan Yang;Jin Zheng
Jiahao Cao;Mingwei Xu;Qi Li;Kun Sun;Yuan Yang;Jin Zheng
中科院分区:
其他
文献类型:
--
作者:
Jiahao Cao;Mingwei Xu;Qi Li;Kun Sun;Yuan Yang;Jin Zheng

文献摘要

被引文献

相似文献

新兴的软件定义网络(SDN)正在被数据中心和云服务提供商采用,以实现灵活的控制。与此同时,当前的SDN设计带来了新的漏洞。在本文中,我们探索了一种基于数据平面的攻击,使用最小的攻击数据包来破坏SDN。为了实现这一点,我们提出了LOFT攻击,计算攻击率的下限溢出流表的基础上推断的网络配置。特别地,每个攻击包总是触发或维持一个流规则的消耗。LOFT可以通过各种网络配置来确保攻击效果,同时降低被捕获的可能性。我们证明了它的可行性和有效性,在一个真实的SDN测试床组成的商业硬件交换机。实验结果表明,LOFT在攻击率仅为几十Kbps的情况下,就能引起网络性能的显著下降和潜在的网络拒绝服务。
The emerging Software-Defined Networking (SDN) is being adopted by data centers and cloud service providers to enable flexible control. Meanwhile, the current SDN design brings new vulnerabilities. In this paper, we explore a stealthy data plane based attack that uses aminimumrate of attack packet to disrupt SDN. To achieve this, we propose the LOFT attack that computes the lower bound of attack rate to overflow flow tables based on the inferred network configurations. Particularly, each attack packet always triggers or maintains consumption of one flow rule. LOFT can ensure the attack effect with various network configurations while reducing the possibility of being captured. We demonstrate its feasibility and effectiveness in a real SDN testbed consisting of commercial hardware switches. The experiment results show that LOFT can incur significant network performance degradation and potential network DoS at an attack rate of only tens of Kbps.