...
首页> 外文期刊>Computer networks >ACST: Audit-based compromised switch tolerance for enhancing data plane robustness in software-defined networking
【24h】

ACST: Audit-based compromised switch tolerance for enhancing data plane robustness in software-defined networking

机译:ACST:基于审核的受损开关容限,可增强软件定义网络中的数据平面稳定性

获取原文
获取原文并翻译 | 示例
           

摘要

Software-defined networking has stimulated the worldwide interests in both academia and industry for its proven advantages. However, switches in data plane are more vulnerable due to malicious attacks. Consequently, the network may consist of a switch misguiding phenomenon: the switches are compromised by the attackers and send the faked statistics while interacting with the controller to mislead the control decision (e.g., optimal routing).In this paper, we introduce an audit-based compromised switch tolerance (ACST) scheme, which aims at tolerating compromised switches and dealing with switch misguiding phenomenon when switches are trustless. Our main idea is to audit the statistics (specifically, state messages) delivered by switches not only to make the controller receive the correct messages but also to identify the compromised switches. Following this idea, we first investigate the switch misguiding phenomenon. Then, we design ACST to ensure that the controller gets the correct state messages even if the compromised switches exist. ACST introduces a special logic plane called fault tolerance proxy plane between data plane and control plane. Each proxy consists of specific function modules, which are used for extracting original state messages and performing statistics auditing. Finally, the proxies output the auditing results, including corrected state messages and the compromised switch IDs. The corresponding algorithm and theoretical proof of its robustness enhancement are also presented. Results show our proposal can successfully resist different manipulating attacks launched by the compromised switches and guarantee a high correctness rate of state messages (approaching 100%). Besides, ACST shows good topological adaptability and produces low overheads. (C) 2019 Elsevier B.V. All rights reserved.
机译:软件定义的网络以其公认的优势已经激发了学术界和行业的全球利益。但是,由于恶意攻击,数据平面中的交换机更容易受到攻击。因此,网络可能包含交换机误导现象:交换机受到攻击者的攻击,并在与控制器交互以误导控制决策(例如,最佳路由)的同时发送伪造的统计信息。基于损害的开关容限(ACST)方案,旨在容忍损害的开关并处理交换机不信任时的交换机误导现象。我们的主要思想是审核交换机提供的统计信息(特别是状态消息),不仅使控制器能够接收正确的消息,而且还能识别出受感染的交换机。遵循这个想法,我们首先研究开关误导现象。然后,我们设计ACST以确保即使存在受损的开关,控制器也能获得正确的状态消息。 ACST在数据平面和控制平面之间引入了一种特殊的逻辑平面,称为容错代理平面。每个代理都包含特定的功能模块,这些功能模块用于提取原始状态消息和执行统计信息审核。最后,代理输出审核结果,包括更正后的状态消息和受损的交换机ID。提出了相应的算法及其鲁棒性增强的理论证明。结果表明,我们的建议可以成功抵御受感染交换机发起的各种操纵攻击,并确保状态消息的正确率很高(接近100%)。此外,ACST具有良好的拓扑适应性,并且开销较低。 (C)2019 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号