首页> 外文期刊>Computer networks >Securing middlebox policy enforcement in SDN
【24h】

Securing middlebox policy enforcement in SDN

机译:在SDN中保护中间箱策略实施

获取原文
获取原文并翻译 | 示例
           

摘要

Software-Defined Networking (SDN) greatly simplifies middlebox policy enforcement. Middleboxes need tag packet headers to avoid forwarding ambiguity on SDN switches. In this paper, we present a new attack, called middlebox-bypass attack, to breach SDN-based middlebox policy enforcement. Such an attack manipulates a compromised switch to locally tag attacking packets without handing them over to the attached middlebox for inspection. Existing SDN security solutions, however, cannot detect the middlebox-bypass attack under practical constraints of efficiency, robustness, and applicability. We design and implement FlowCloak, the first protocol for per-packet real-time detection and prevention of middlebox-bypass attacks. FlowCloak enables middleboxes to generate tags that are probabilistically unknown to an attacker and confines it to only random guessing. We propose a multi-tag verification technique to address the tradeoff between FlowCloak robustness and TCAM usage by tag verification rules on the egress switch. Experiment results show that dozens of verification rules can confine the attacking probability under 0.1%. We further explore implementation techniques of packet looping and field swapping that can enable a flow table pipeline on a single TCAM and mitigate packet correlation, respectively. FlowCloak imposes only a 0.01 ms packet processing delay on middleboxes and no obvious delay on the egress switch.
机译:软件定义的网络(SDN)大大简化了中间箱策略实施。 Moditboxes需要标记分组标题以避免在SDN交换机上转发歧义。在本文中,我们展示了一个名为Moditbox-Bypass攻击的新攻击,以违反基于SDN的中间箱策略实施。这样的攻击操纵一个受到妥协的开关到本地标签攻击分组,而不将它们交给所连接的中间箱进行检查。但是,现有的SDN安全解决方案无法在实际限制的效率,稳健性和适用性下检测中间箱旁路攻击。我们设计和实施FlowCloak,这是每包实时检测和防止中间箱旁路攻击的第一个协议。 FlowCloak使中间盒能够生成攻击者概率不为人知的标签,并将其限制在随机猜测中。我们提出了一种多标签验证技术,以通过在出口交换机上标记验证规则来解决流线鲁棒性和TCAM使用之间的权衡。实验结果表明,几十条验证规则可以将攻击概率限制在0.1%以下。我们进一步探索了分组循环和场交换的实现技术,其可以分别在单个TCAM上启用流量表流水线并分别减轻分组相关性。 Flowcloak仅在中间盒上仅施加0.01毫秒的包装延迟,并且出口开关上没有明显的延迟。

著录项

  • 来源
    《Computer networks》 |2021年第5期|108099.1-108099.14|共14页
  • 作者单位

    College of Computer Science and Technology Zhejiang University Hangzhou 310027 China;

    College of Computer Science and Technology Zhejiang University Hangzhou 310027 China;

    College of Computer Science and Technology Zhejiang University Hangzhou 310027 China;

    Department of Electrical and Computer Engineering Stony Brook University Stony Brook NY 11794 USA;

    College of Computer Science and Technology Zhejiang University Hangzhou 310027 China;

    School of Information Science and Engineering Central South University Changsha 410083 China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Middlebox policy enforcement; Security; Software-defined networking;

    机译:中间箱策略实施;安全;软件定义的网络;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号