Adversarial Network Forensics in Software Defined Networking

Adversarial Network Forensics in Software Defined Networking
复制标题

DOI:
10.1145/3050220.3050223
复制
发表时间:
2017-04
期刊:
Proceedings of the Symposium on SDN Research
影响因子:
--
通讯作者:
S. Achleitner;T. F. Porta;T. Jaeger;P. Mcdaniel
S. Achleitner;T. F. Porta;T. Jaeger;P. Mcdaniel
中科院分区:
其他
文献类型:
--
作者:
S. Achleitner;T. F. Porta;T. Jaeger;P. Mcdaniel

文献摘要

被引文献

相似文献

软件定义网络 (SDN) 及其流行的实施 OpenFlow 代表了现代网络设计和实施的基础。基于 SDN 的网络的重要部分是流量规则,使网络元素能够引导和控制流量,并在网络中的任何入口点以细粒度部署策略执行点。此类使用 OpenFlow 规则实现的应用程序已经成为广泛使用的 SDN 控制器(例如 Floodlight 或 OpenDayLight)的组成部分。网络策略的实施细节体现在流规则的组成中,这些信息的泄露为对手提供了显着的攻击优势,例如绕过访问控制列表(ACL)、重建负载均衡器的资源分布或暴露移动目标防御技术。在本文中,我们通过展示网络用户如何在不事先了解 SDN 控制器或其架构的情况下重建流规则的详细组成,介绍了 SDN 上的新攻击向量。据我们所知,在SDN中,迄今为止尚未考虑过此类侦察技术。我们介绍SDNMap,一个开源扫描器,它能够通过执行主动探测和监听网络流量来准确地重建流规则的详细组成。我们在许多现实世界的 SDN 应用程序中证明,这种能力为对手提供了显着的攻击优势,并讨论了防止引入侦察技术的方法。我们的 SDNMap 扫描仪能够重建网络端点之间的流规则,准确度超过 96%。
Software Defined Networking (SDN), and its popular implementation OpenFlow, represent the foundation for the design and implementation of modern networks. The essential part of an SDN-based network are flow rules that enable network elements to steer and control the traffic and deploy policy enforcement points with a fine granularity at any entry-point in a network. Such applications, implemented with the usage of OpenFlow rules, are already integral components of widely used SDN controllers such as Floodlight or OpenDayLight. The implementation details of network policies are reflected in the composition of flow rules and leakage of such information provides adversaries with a significant attack advantage such as bypassing Access Control Lists (ACL), reconstructing the resource distribution of Load Balancers or revealing of Moving Target Defense techniques. In this paper we introduce a new attack vector on SDN by showing how the detailed composition of flow rules can be reconstructed by network users without any prior knowledge of the SDN controller or its architecture. To our best knowledge, in SDN, such reconnaissance techniques have not been considered so far. We introduce SDNMap, an open-source scanner that is able to accurately reconstruct the detailed composition of flow rules by performing active probing and listening to the network traffic. We demonstrate in a number of real-world SDN applications that this ability provides adversaries with a significant attack advantage and discuss ways to prevent the introduced reconnaissance techniques. Our SDNMap scanner is able to reconstruct flow rules between network endpoints with an accuracy of over 96%.