Fast IP Hopping Randomization to Secure Hop-by-Hop Access in SDN

Fast IP Hopping Randomization to Secure Hop-by-Hop Access in SDN
复制标题

DOI:
10.1109/tnsm.2018.2889842
复制
发表时间:
2019-03-01
影响因子:
5.3
通讯作者:
Babu, Bhavana Babu Ashok
Babu, Bhavana Babu Ashok
中科院分区:
计算机科学2区
文献类型:
--
作者:
Chang, Sang-Yoon;Park, Younghee;Babu, Bhavana Babu Ashok

文献摘要

被引文献

相似文献

移动目标防御(MTD)对于挫败网络侦察和防止未经授权的访问非常有用。虽然之前在MTD方面的研究侧重于保护终端节点,但我们利用软件定义的网络在数据平面交换机上实施MTD,这显著降低了控制器的通信开销,并实现了更快的防御响应,以减少攻击影响。该文不仅将MTD的IP地址随机化,而且通过生成基于哈希链的同步签名,将IP地址用于跨网络路径上的节点进行同步。我们的方案是实用的,因为它建立在用于随机化的现有IP地址之上并对其进行编码,以构建独立于路由/流规则实现的模块化解决方案,并且除了种子分发(可以脱机发生)之外,不会产生额外的联网开销。我们的方案也是有效的(攻击者实现及时网络侦察所需的成本比以前由控制器执行MTD随机化的最新技术增加了一个数量级以上)并且可扩展(我们方案的相对开销成本随着网络的增长而变得更小)。我们分析了我们的方案,并在基于Open vSwitch的测试床上和在CloudLab上进行了实现和实验,以验证这些特性。
Moving target defense (MTD) is useful for thwarting network reconnaissance and preventing unauthorized access. While previous research in MTD focuses on protecting the endnodes, we leverage software-defined networking to implement MTD on the data-plane switches, which significantly decreases the controller communication overhead and enables quicker defense response to reduce the attack impact. This paper not only randomizes the IP addresses for MTD but also uses the IP addresses for synchronization across the nodes in the networking path by generating hash-chain-based synchronization signatures. Our scheme is practical as it builds on and encodes the existing IP addresses for randomization to construct a modular solution independent to the routing/flow rule implementation and does not incur additional networking overhead except for the seed distribution (which can occur offline). Our scheme is also effective (the attacker's required cost to achieve timely network reconnaissance increases by more than an order of magnitude than the previous state-of-the-art having the controller actuate the MTD randomization) and scalable (the relative overhead cost of our scheme becomes smaller as the network grows). We analyze our scheme and implement and experiment it on an Open vSwitch-based testbed and on CloudLab to validate these properties.