A survey on security applications of P4 programmable switches and a STRIDE-based vulnerability assessment

A survey on security applications of P4 programmable switches and a STRIDE-based vulnerability assessment
复制标题

DOI:
10.1016/j.comnet.2022.108800
复制
发表时间:
2022-02
期刊:
Comput. Networks
影响因子:
--
通讯作者:
Ali AlSabeh;Joseph Khoury;Elie F. Kfoury;J. Crichigno;E. Bou-Harb
Ali AlSabeh;Joseph Khoury;Elie F. Kfoury;J. Crichigno;E. Bou-Harb
中科院分区:
其他
文献类型:
--
作者:
Ali AlSabeh;Joseph Khoury;Elie F. Kfoury;J. Crichigno;E. Bou-Harb

文献摘要

相似文献

物联网、云系统、数据中心和5G网络的出现,增加了在协议栈的各个层次快速开发新应用和协议的需求。然而,传统的固定功能数据平面的特征在于少数芯片制造商的冗长且昂贵的开发过程。最近,数据平面可编程性引起了极大的关注,允许网络所有者使用P4(事实上的数据平面编程语言)运行定制的数据包处理功能。网络安全是利用可编程交换机功能的关键研究领域之一。例如,在短时间内实施的新的防火墙和安全隧道,以太比特速率发生的DDoS攻击的缓解技术,每秒跟踪数十万连接的定制防火墙,以及以线速运行的流量匿名系统。此外,应用程序可以在现场重新配置,而无需额外的硬件升级,从而促进了针对不可预见的攻击和漏洞的新防御部署。此外,这些安全应用程序是由网络所有者谁可以满足他们的特定需求,而不是由芯片制造商。尽管可编程数据平面交换机的令人印象深刻的优点,文献一直缺乏一个全面的调查安全应用。为此,本文提供了一个简明的背景下,可编程开关和它们的主要特点,是相关的安全。然后,它提供了一个分类法,该分类法对与使用P4开发的安全应用程序相关的文章进行调查、分类和分析。此外,本文采用STRIDE分析来检查与一般P4应用程序相关的漏洞(例如,拥塞控制、负载平衡、网络内高速缓存),并提出合理的补救方法。此外,与可编程数据平面相关的挑战,这些挑战对安全实施的影响,以及消除或减轻它们的方案进行了讨论。最后,本文讨论了未来的努力和开放的研究问题。
The emergence of the IoT, cloud systems, data centers, and 5G networks is increasing the demand for a rapid development of new applications and protocols at all levels of the protocol stack. However, traditional fixed-function data planes have been characterized by a lengthy and costly development process at the hand of few chip manufacturers. Recently, data plane programmability has attracted significant attention, permitting network owners to run customized packet processing functions using P4, thede factodata plane programming language. Network security is one of the key research areas exploiting the capabilities of programmable switches. Examples include new encapsulations and secure tunnels implemented in short times, mitigation techniques for DDoS attacks that occur at terabit rates, customized firewalls that track hundreds of thousands of connections per second, and traffic anonymization systems that operate at line rate. Moreover, applications can be reconfigured in the field without additional hardware upgrades, facilitating the deployment of new defenses against unforeseen attacks and vulnerabilities. Furthermore, these security applications are designed by network owners who can meet their specific requirements, rather than by chip manufacturers.Despite the impressive advantages of programmable data plane switches, the literature has been missing a comprehensive survey on security applications. To this end, this paper provides a concise background on programmable switches and their main features that are relevant to security. It then presents a taxonomy that surveys, classifies, and analyzes articles related to security applications developed with P4. Additionally, the paper employs a STRIDE analysis to examine vulnerabilities related to general P4 applications (e.g., congestion control, load balancing, in-network cache) and proposes plausible remediation approaches. Furthermore, challenges associated with programmable data planes, the impact of these challenges on security implementations, and schemes to eliminate or mitigate them are discussed. Finally, the paper discusses future endeavors and open research problems.