Flow Table Security in SDN: Adversarial Reconnaissance and Intelligent Attacks

Flow Table Security in SDN: Adversarial Reconnaissance and Intelligent Attacks
复制标题

DOI:
10.1109/tnet.2021.3099717
复制
发表时间:
2021-12
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
Mingli Yu;Tian Xie;T. He;P. Mcdaniel;Quinn K. Burke
Mingli Yu;Tian Xie;T. He;P. Mcdaniel;Quinn K. Burke
中科院分区:
其他
文献类型:
--
作者:
Mingli Yu;Tian Xie;T. He;P. Mcdaniel;Quinn K. Burke

文献摘要

相似文献

SDN架构的性能驱动设计留下了许多安全漏洞,其中一个值得注意的是控制器和交换机之间的通信瓶颈。作为控制器和交换机之间的高速缓存,流表通过在每个交换机处高速缓存从控制器接收的流规则来缓解该瓶颈,但是由于底层存储介质的高成本和功耗,流表的大小非常有限。因此,它是一个容易攻击的目标。观察到许多现有的防御是基于简单化的攻击模型,我们开发了一个模型的智能攻击,利用特定的缓存一样的行为的流表来推断其内部配置和状态,然后相应地设计攻击参数。我们的评估表明,这种攻击可以准确地暴露目标流表的内部参数,并以最小的努力造成可测量的损害。
The performance-driven design of SDN architectures leaves many security vulnerabilities, a notable one being the communication bottleneck between the controller and the switches. Functioning as a cache between the controller and the switches, the flow table mitigates this bottleneck by caching flow rules received from the controller at each switch, but is very limited in size due to the high cost and power consumption of the underlying storage medium. It thus presents an easy target for attacks. Observing that many existing defenses are based on simplistic attack models, we develop a model of intelligent attacks that exploit specific cache-like behaviors of the flow table to infer its internal configuration and state, and then design attack parameters accordingly. Our evaluations show that such attacks can accurately expose the internal parameters of the target flow table and cause measurable damage with the minimum effort.