首页> 外文会议>IEEE International Conference on Network Protocols >Fingerprinting Software-Defined Networks
【24h】

Fingerprinting Software-Defined Networks

机译:指纹软件定义的网络

获取原文

摘要

In this paper, we study the feasibility of fingerprinting of controller-switch interactions in SDN networks by a remote adversary whose aim is to acquire knowledge about specific flow rules that are installed at the switches. This knowledge empowers the adversary with a better understanding of the network's packet-forwarding logic and exposes the network to a number of threats. In our study, we collect measurements from hosts located across the globe using a realistic SDN network comprising of OpenFlow hardware switches. We show that, by leveraging information from the RTT and packet-pair dispersion of the exchanged packets, fingerprinting attacks on SDN networks succeed with overwhelming probability. We also show that these attacks are not restricted to active adversaries, but can be equally mounted by passive adversaries that only monitor traffic exchanged with the SDN network. Finally, we sketch an efficient countermeasure to strengthen SDN networks against fingerprinting.
机译:在本文中,我们研究了远程对手在SDN网络中对控制器-交换机交互进行指纹识别的可行性,其目的是获取有关安装在交换机上的特定流规则的知识。这些知识使攻击者可以更好地了解网络的数据包转发逻辑,并使网络面临多种威胁。在我们的研究中,我们使用由OpenFlow硬件交换机组成的逼真的SDN网络从全球各地的主机收集测量值。我们显示出,通过利用来自RTT的信息和交换数据包的数据包对散布,SDN网络上的指纹攻击成功的可能性非常大。我们还表明,这些攻击不仅限于主动攻击者,还可以由仅监视与SDN网络交换的流量的被动攻击者同样地进行攻击。最后,我们勾勒出一种有效的对策,以增强SDN网络的抗指纹能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号