Memory Forensics of the OpenDaylight Software-Defined Networking (SDN) Controller

Memory Forensics of the OpenDaylight Software-Defined Networking (SDN) Controller
复制标题

DOI:
10.1145/3600160.3600196
复制
发表时间:
2023-08
期刊:
Proceedings of the 18th International Conference on Availability, Reliability and Security
影响因子:
--
通讯作者:
Abdullah Alshaya;Adam Kardorff;Christian Facundus;I. Baggili;Golden Richard III
Abdullah Alshaya;Adam Kardorff;Christian Facundus;I. Baggili;Golden Richard III
中科院分区:
其他
文献类型:
--
作者:
Abdullah Alshaya;Adam Kardorff;Christian Facundus;I. Baggili;Golden Richard III

文献摘要

相似文献

软件定义网络(SDN)通过保持控制平面和数据分离来抽象底层网络硬件。SDN使用控制平面来引导网络流量,而OpenFlow交换机和路由器通过转发数据包在系统中扮演被动角色。虚拟化系统上控制平面的集中化为数字取证(DF)提供了获取和分析控制器内存的机会。这提供了关于SDN操作的法医相关数据。在我们的工作中,我们检查了OpenDaylight(ODL)SDN控制器,以确定可以从控制器的内存中提取哪些取证相关信息。这是通过创建具有不同网络配置的控制器内存样本,并分析内存样本,然后构建SDN控制器网络发现工具(SCoNDT)来实现的。SCoNDT在内存转储中搜索ODL控制器的主机跟踪服务。此服务保存连接到网络的每台主机的信息,例如其内部IP地址、MAC地址以及首次和最后一次网络连接的日期和时间。然后生成HTML报告。SCoNDT在具有各种网络配置的内存样本上进行了评估,在重建主机IP、用户名和散列密码方面表现出很高的效率。
Software-Defined Networking (SDN) abstracts the underlying networking hardware by keeping the control plane and the data separated. SDNs use the control plane to direct network traffic, while OpenFlow switches and routers play a passive role in the system by forwarding packets. The centralization of the control plane on virtualized systems provide Digital Forensics (DF) an opportunity at acquiring and analyzing the memory of a controller. This provides forensically relevant data regarding the SDN’s operation. In our work, we examined the OpenDaylight (ODL) SDN controller to determine what forensically relevant information may be extracted from the controller’s memory. This was accomplished by creating controller memory samples with different networking configurations, and analyzing the memory samples, then constructing an SDN-Controller-Network-Discovery-Tool (SCoNDT). SCoNDT searches a memory dump for the ODL controller’s host tracker service. This service holds information on each host connected to the network, such as its internal IP address, MAC address, and the dates and times of its first and last network connections. It then generates an HTML report. SCoNDT was evaluated on memory samples with various network configurations and showed high efficacy in reconstructing the host IPs, the usernames, and hashed passwords.