Towards rule enforcement verification for software defined networks

Towards rule enforcement verification for software defined networks
复制标题

DOI:
10.1109/infocom.2017.8056994
复制
发表时间:
2017-05
期刊:
IEEE INFOCOM 2017 - IEEE Conference on Computer Communications
影响因子:
--
通讯作者:
P. Zhang
P. Zhang
中科院分区:
其他
文献类型:
--
作者:
P. Zhang

文献摘要

被引文献

相似文献

软件定义网络(SDN)通过引入集中式和可编程的网络控制来重塑僵化的网络架构。尽管有巨大的好处,但SDN也为我们所说的规则修改攻击打开了大门,这是一种被社区很大程度上忽视的攻击。在这种攻击中,对手可以通过利用交换机操作系统和控制通道的实现漏洞来修改规则。因此,数据包可能会偏离其原始路径,从而违反网络策略。为了防御规则修改攻击,本文提出了一种新的安全原语规则实施验证(REV)。REV允许控制器使用消息认证码(MAC)检查交换机是否执行了它安装的规则。由于使用标准的MAC会导致大量的交换机到控制器的流量,本文提出了一种新的压缩MAC,它允许交换机压缩MAC之前,报告给控制器。实验结果表明,基于压缩MAC的REV协议可以使交换机到控制器的通信量减少97%,验证吞吐量提高5%。
Software defined networks (SDNs) reshape the ossified network architectures, by introducing centralized and programmable network control. Despite the huge benefits, SDNs also open doors to what we call rule modification attack, an attack largely overlooked by the community. In such an attack, the adversary can modify rules by exploiting implementation vulnerabilities of switch OSes and control channels. As a result, packets may deviate from their original paths, thereby violating network policies. To defend against rule modification attack, this paper introduces a new security primitive named rule enforcement verification (REV). REV allows a controller to check whether switches have enforced the rules installed by it, using message authentication code (MAC). Since using standard MACs will incur heavy switch-to-controller traffic, this paper proposes a new compressive MAC, which allows switches to compress MACs before reporting to the controller. Experiments show that REV based on compressive MAC can achieve a 97% reduction in switch-to-controller traffic, and a Sx increase in verification throughput.