【24h】

Slow TCAM Exhaustion DDoS Attack

机译:慢速TCAM疲惫DDOS攻击

获取原文

摘要

Software Defined Networks (SDN) facilitate network management by decoupling the data plane which forwards packets using efficient switches from the control plane by leaving the decisions on how packets should be forwarded to a (centralized) controller. However, due to limitations on the number of forwarding rules a switch can store in its TCAM memory, SDN networks have been subject to saturation and TCAM exhaustion attacks where the attacker is able to deny service by forcing a target switch to install a great number of rules. An underlying assumption is that these attacks are carried out by sending a high rate of unique packets. This paper shows that this assumption is not necessarily true and that SDNs are vulnerable to Slow TCAM exhaustion attacks (Slow-TCAM). We analyse this attack arguing that existing defenses for saturation and TCAM exhaustion attacks are not able to mitigate Slow-TCAM due to its relatively low traffic rate. We then propose a novel defense called SIFT based on selective strategies demonstrating its effectiveness against the Slow-TCAM attack.
机译:软件定义的网络(SDN)通过将数据平面解耦,通过离开控制平面来释放关于应该如何转发到(集中式)控制器的决定来促进使用高效交换的数据平面来促进网络管理。但是,由于转发规则的数量的限制,交换机可以存储在其TCAM内存中,SDN网络一直受到饱和度和TCAM耗尽攻击,其中攻击者能够迫使目标交换机安装大量的攻击者。规则。潜在的假设是通过发送高唯一数据包来执行这些攻击。本文表明,此假设不一定是真,并且SDNS容易受到TCAM耗尽攻击(慢速TCAM)的影响。我们分析了这种攻击,争论饱和度和TCAM耗尽攻击的现有防御不能降低慢速TCAM由于其交通率相对较低。然后,我们提出了一种基于选择性策略的新型防御,旨在证明其对缓慢TCAM攻击的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号