Unexpected Data Dependency Creation and Chaining: A New Attack to SDN

Unexpected Data Dependency Creation and Chaining: A New Attack to SDN
复制标题

DOI:
10.1109/sp40000.2020.00017
复制
发表时间:
2020-05
期刊:
2020 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Feng Xiao;Jinquan Zhang;Jianwei Huang;G. Gu;Dinghao Wu;Peng Liu
Feng Xiao;Jinquan Zhang;Jianwei Huang;G. Gu;Dinghao Wu;Peng Liu
中科院分区:
其他
文献类型:
--
作者:
Feng Xiao;Jinquan Zhang;Jianwei Huang;G. Gu;Dinghao Wu;Peng Liu

文献摘要

被引文献

相似文献

软件定义的网络(SDN)是一种新兴网络体系结构,可通过逻辑集中的控制器提供可编程网络。随着SDN变得更加突出,其安全漏洞比以往任何时候都变得更加明显。作为软件定义网络的“大脑”,(网络的控制平面)如何暴露于外部输入(即数据平面消息)与网络的安全性直接相关。幸运的是,由于某些独特的SDN设计选择(例如,控制平面和数据平面分离),攻击者经常难以找到通往控制平面内隐藏在控制平面内的脆弱逻辑的可触及路径。在本文中,我们证明了可能的可能性一个仅控制商品网络设备(主机或开关)的弱对手,通过恶意提高控制平面的可及性来攻击以前无法实现的控制平面组件。我们介绍了D2C2(数据依赖性创建和链接)攻击,该攻击利用了一些广泛使用的SDN协议功能(例如自定义字段)创建和链链,以实现更大的可及性。我们已经开发了一种新颖的工具Svhunter,可以有效地识别D2C2漏洞。到目前为止,我们已经在三个主流开源SDN控制器(即Onos,Floodlight和OpenDaylight)以及一个安全增强控制器(即SE-Floodlight)上评估了SVHUNTER。 SVHUNTER检测到18个以前未知的漏洞,所有这些漏洞都可以远程利用,以发起严重的攻击,例如执行任意命令,去除机密文件和崩溃的SDN服务。
Software-Defined Networking (SDN) is an emerging network architecture that provides programmable networking through a logically centralized controller. As SDN becomes more prominent, its security vulnerabilities become more evident than ever. Serving as the "brain" of a software-defined network, how the control plane (of the network) is exposed to external inputs (i.e., data plane messages) is directly correlated with how secure the network is. Fortunately, due to some unique SDN design choices (e.g., control plane and data plane separation), attackers often struggle to find a reachable path to those vulnerable logic hidden deeply within the control plane.In this paper, we demonstrate that it is possible for a weak adversary who only controls a commodity network device (host or switch) to attack previously unreachable control plane components by maliciously increasing reachability in the control plane. We introduce D2C2 (data dependency creation and chaining) attack, which leverages some widely-used SDN protocol features (e.g., custom fields) to create and chain unexpected data dependencies in order to achieve greater reachability. We have developed a novel tool, SVHunter, which can effectively identify D2C2 vulnerabilities. Till now we have evaluated SVHunter on three mainstream open-source SDN controllers (i.e., ONOS, Floodlight, and Opendaylight) as well as one security-enhanced controller (i.e., SE-Floodlight). SVHunter detects 18 previously unknown vulnerabilities, all of which can be exploited remotely to launch serious attacks such as executing arbitrary commands, exfiltrating confidential files, and crashing SDN services.