The CrossPath Attack: Disrupting the SDN Control Channel via Shared Links

The CrossPath Attack: Disrupting the SDN Control Channel via Shared Links
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Jiahao Cao;Qi Li;Renjie Xie;Kun Sun;G. Gu;Mingwei Xu;Yuan Yang
Jiahao Cao;Qi Li;Renjie Xie;Kun Sun;G. Gu;Mingwei Xu;Yuan Yang
中科院分区:
其他
文献类型:
--
作者:
Jiahao Cao;Qi Li;Renjie Xie;Kun Sun;G. Gu;Mingwei Xu;Yuan Yang

文献摘要

被引文献

相似文献

软件定义网络(SDN)通过一个集中式控制器经由控制通道控制整个网络,从而实现网络创新。由于控制通道承载所有网络控制流量,其安全性和可靠性至关重要。在文献中我们首次提出了交叉路径攻击,该攻击通过利用控制流量和数据流量路径中的共享链路来破坏SDN控制通道。在这种攻击中,精心构造的数据流量可以隐式地破坏共享链路中控制流量的转发。由于数据流量不进入控制通道,这种攻击具有隐蔽性,控制器不容易察觉。为了识别包含共享链路的目标攻击路径,我们开发了一种名为对抗路径侦察的新技术。理论分析和实验结果都证明了其识别目标路径的可行性和有效性。我们在一个真实的SDN测试平台上系统地研究了攻击对各种网络应用的影响。实验表明,攻击显著降低了现有网络应用的性能,并导致严重的网络异常,例如路由黑洞、流表重置,甚至是全网拒绝服务(DoS)。
Software-Defined Networking (SDN) enables network innovations with a centralized controller controlling the whole network through the control channel. Because the control channel delivers all network control traffic, its security and reliability are of great importance. For the first time in the literature, we propose the CrossPath attack that disrupts the SDN control channel by exploiting the shared links in paths of control traffic and data traffic. In this attack, crafted data traffic can implicitly disrupt the forwarding of control traffic in the shared links. As the data traffic does not enter the control channel, the attack is stealthy and cannot be easily perceived by the controller. In order to identify the target paths containing the shared links to attack, we develop a novel technique called adversarial path reconnaissance. Both theoretic analysis and experimental results demonstrate its feasibility and efficiency of identifying the target paths. We systematically study the impacts of the attack on various network applications in a real SDN testbed. Experiments show the attack significantly degrades the performance of existing network applications and causes serious network anomalies, e.g., routing blackhole, flow table resetting, and even network-wide DoS.