Link Latency Attack in Software-Defined Networks

Link Latency Attack in Software-Defined Networks
复制标题

DOI:
10.23919/cnsm52442.2021.9615598
复制
发表时间:
2021-10
期刊:
2021 17th International Conference on Network and Service Management (CNSM)
影响因子:
--
通讯作者:
Sanaz Soltani;M. Shojafar;H. Mostafaei;Zahra Pooranian;R. Tafazolli
Sanaz Soltani;M. Shojafar;H. Mostafaei;Zahra Pooranian;R. Tafazolli
中科院分区:
其他
文献类型:
--
作者:
Sanaz Soltani;M. Shojafar;H. Mostafaei;Zahra Pooranian;R. Tafazolli

文献摘要

相似文献

软件定义网络(SDN)已经在不同的领域得到了应用,包括有线和无线网络。SDN控制器具有网络拓扑的全局视图,这很容易受到拓扑中毒攻击,例如链路制造和主机位置劫持。攻击者可以利用这些攻击来监视流或丢弃流。然而,目前的防御系统,如TopoGuard和TopoGuard+可以检测到这种攻击。在本文中,我们介绍了链路延迟攻击(LLA),它可以成功地绕过系统的上述防御机制。在LLA中,攻击者可以在网络中添加假链接,并从网络拓扑中破坏控制器的视图。这可以通过破坏终端主机来实现,而不需要攻击启用sdn的交换机。我们开发了一个基于机器学习的链路保护(MLLG)系统,为LLA提供所需的防御。利用Mininet仿真网络对系统进行了性能测试,结果表明系统检测攻击的准确率达到98.22%。有趣的是,MLLG将TopoGuard+的准确率提高了16%。
Software-Defined Networking (SDN) has found applications in different domains, including wired- and wireless networks. The SDN controller has a global view of the network topology, which is vulnerable to topology poisoning attacks, e.g., link fabrication and host-location hijacking. The adversaries can leverage these attacks to monitor the flows or drop them. However, current defence systems such as TopoGuard and TopoGuard+ can detect such attacks. In this paper, we introduce the Link Latency Attack (LLA) that can successfully bypass the systems' defence mechanisms above. In LLA, the adversary can add a fake link into the network and corrupt the controller's view from the network topology. This can be accomplished by compromising the end hosts without the need to attack the SDN-enabled switches. We develop a Machine Learning-based Link Guard (MLLG) system to provide the required defence for LLA. We test the performance of our system using an emulated network on Mininet, and the obtained results show an accuracy of 98.22% in detecting the attack. Interestingly, MLLG improves 16% the accuracy of TopoGuard+.