NetHide: Secure and Practical Network Topology Obfuscation

NetHide: Secure and Practical Network Topology Obfuscation
复制标题

DOI:
--
复制
发表时间:
2018-08
期刊:
--
影响因子:
--
通讯作者:
Roland Meier;Petar Tsankov;Vincent Lenders;Laurent Vanbever;Martin T. Vechev
Roland Meier;Petar Tsankov;Vincent Lenders;Laurent Vanbever;Martin T. Vechev
中科院分区:
其他
文献类型:
--
作者:
Roland Meier;Petar Tsankov;Vincent Lenders;Laurent Vanbever;Martin T. Vechev

文献摘要

被引文献

相似文献

简单的路径跟踪工具(如traceroute)允许恶意用户远程推断网络拓扑,并使用这些知识来制作高级拒绝服务(DoS)攻击,如链路泛滥攻击(LFA)。然而,尽管有风险,大多数网络运营商仍然允许路径跟踪,因为它是一个必不可少的网络调试工具。在本文中,我们提出了NetHide,这是一个网络拓扑混淆框架,可以减轻LFA,同时保留路径跟踪工具的实用性。NetHide背后的关键思想是将网络混淆作为一个多目标优化问题,允许在安全性(编码为硬约束)和可用性(编码为软约束)之间进行灵活的权衡。虽然解决这个问题是困难的,我们表明,NetHide可以混淆拓扑结构的规模只考虑候选解决方案的一个子集,而不会降低混淆质量。在实践中,NetHide通过直接在数据平面中拦截和修改路径跟踪探测来混淆拓扑。我们表明,这个过程可以在线速,在一个无状态的方式,利用最新一代的可编程网络设备。我们完全实现了NetHide,并在实际拓扑上对其进行了评估。我们的研究结果表明,NetHide能够混淆大型拓扑(> 150个节点),同时保持近乎完美的调试能力。特别是,我们表明,运营商仍然可以精确地追溯> 90%的链路故障,尽管混淆。
Simple path tracing tools such as traceroute allow malicious users to infer network topologies remotely and use that knowledge to craft advanced denial-of-service (DoS) attacks such as Link-Flooding Attacks (LFAs). Yet, despite the risk, most network operators still allow path tracing as it is an essential network debugging tool. In this paper, we present NetHide, a network topology obfuscation framework that mitigates LFAs while preserving the practicality of path tracing tools. The key idea behind NetHide is to formulate network obfuscation as a multi-objective optimization problem that allows for a flexible tradeoff between security (encoded as hard constraints) and usability (encoded as soft constraints). While solving this problem exactly is hard, we show that NetHide can obfuscate topologies at scale by only considering a subset of the candidate solutions and without reducing obfuscation quality. In practice, NetHide obfuscates the topology by intercepting and modifying path tracing probes directly in the data plane. We show that this process can be done at line-rate, in a stateless fashion, by leveraging the latest generation of programmable network devices. We fully implemented NetHide and evaluated it on realistic topologies. Our results show that NetHide is able to obfuscate large topologies (> 150 nodes) while preserving near-perfect debugging capabilities. In particular, we show that operators can still precisely trace back > 90% of link failures despite obfuscation.