Towards Fine-grained Network Security Forensics and Diagnosis in the SDN Era

Towards Fine-grained Network Security Forensics and Diagnosis in the SDN Era
复制标题

DOI:
10.1145/3243734.3243749
复制
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Haopei Wang;Guangliang Yang;Phakpoom Chinprutthiwong;Lei Xu;Yangyong Zhang;G. Gu
Haopei Wang;Guangliang Yang;Phakpoom Chinprutthiwong;Lei Xu;Yangyong Zhang;G. Gu
中科院分区:
其他
文献类型:
--
作者:
Haopei Wang;Guangliang Yang;Phakpoom Chinprutthiwong;Lei Xu;Yangyong Zhang;G. Gu

文献摘要

被引文献

相似文献

在传统网络中诊断网络安全问题很困难。在新兴软件定义的网络中,它更令人沮丧。 SDN框架的数据/控制平面解耦使传统网络故障排除工具不适合查明控制平面中的根本原因。在本文中,我们提出了前沿,它在SDN网络中提供了流量级取证和诊断功能。与仅涉及网络级别或主机级别的传统取证工具不同,远见监视器和记录了运行时活动及其因果关系依赖性,涉及SDN控制平面和数据平面。从可能是由安全问题引起的转发问题(例如断开连接)开始,企业可以通过因果关系回溯到控制和数据平面中的先前活动,并确定问题的根本原因。企业还提供了一个用户友好的接口,该接口允许用户指定检测点并诊断复杂的网络问题。我们在泛光灯控制器之上实现了一个远见的原型系统,并使用它来诊断几个真实的控制平面攻击。我们表明,企业可以迅速显示活动的因果关系,并有助于缩小可能是根本原因的可疑活动范围。我们的绩效评估表明,Forenguard将为SDN控制平面增加较小的运行时开销,并且可以在各种网络工作负载中进行良好的扩展。
Diagnosing network security issues in traditional networks is difficult. It is even more frustrating in the emerging Software Defined Networks. The data/control plane decoupling of the SDN framework makes the traditional network troubleshooting tools unsuitable for pinpointing the root cause in the control plane. In this paper, we propose ForenGuard, which provides flow-level forensics and diagnosis functions in SDN networks. Unlike traditional forensics tools that only involve either network level or host level, ForenGuard monitors and records the runtime activities and their causal dependencies involving both the SDN control plane and data plane. Starting with a forwarding problem (e.g., disconnection) which could be caused by a security issue, ForenGuard can backtrack the previous activities in both the control and data plane through causal relationships and pinpoint the root cause of the problem. ForenGuard also provides a user-friendly interface that allows users to specify the detection point and diagnose complicated network problems. We implement a prototype system of ForenGuard on top of the Floodlight controller and use it to diagnose several real control plane attacks. We show that ForenGuard can quickly display causal relationships of activities and help to narrow down the range of suspicious activities that could be the root causes. Our performance evaluation shows that ForenGuard will add minor runtime overhead to the SDN control plane and can scale well in various network workloads.