首页> 外文期刊>Emerging Topics in Computing, IEEE Transactions on >A Novel Stealthy Attack to Gather SDN Configuration-Information
【24h】

A Novel Stealthy Attack to Gather SDN Configuration-Information

机译:一个小说隐秘的攻击来收集SDN配置信息

获取原文
获取原文并翻译 | 示例
       

摘要

Software Defined Networking (SDN) is a recent network architecture based on the separation of forwarding functions from network logic, and provides high flexibility in the management of the network. In this paper, we show how an attacker can exploit SDN programmability to obtain detailed knowledge about the network behaviour. In particular, we introduce a novel attack, named Know Your Enemy (KYE), which allows an attacker to gather vital information about the configuration of the network. Through the KYE attack, an attacker can obtain information ranging from the configuration of security tools, such as attack detection thresholds for network scanning, to general network policies like QoS and network virtualization. Additionally, we show that the KYE attack can be performed in a stealthy fashion, allowing an attacker to learn configuration secrets without being detected. We underline that the vulnerability exploited by the KYE attack is proper of SDN and is not present in legacy networks. Finally, we address the KYE attack by proposing an active defense countermeasure based on network flows obfuscation, which considerably increases the complexity for a successful attack. Our solution offers provable security guarantees that can be tailored to the needs of the specific network under consideration.
机译:软件定义的网络(SDN)是最近的网络架构,基于从网络逻辑的转发功能的分离,并在网络管理中提供了高灵活性。在本文中,我们展示了攻击者如何利用SDN可编程性以获取有关网络行为的详细知识。特别是,我们介绍了一个新颖的攻击,命名为您的敌人(Kye),允许攻击者收集有关网络配置的重要信息。通过Kye攻击,攻击者可以从安全工具的配置中获取信息,例如攻击网络扫描的攻击检测阈值,以QoS和网络虚拟化等一般网络策略。此外,我们表明Kye攻击可以以隐身的方式执行,允许攻击者学习未检测到的配置秘密。我们强调了KYE攻击利用的漏洞是正确的SDN,并且不存在于遗留网络中。最后,我们通过提出基于网络流量的主动防御对策来解决KYE攻击,这显着增加了成功攻击的复杂性。我们的解决方案提供了可提供的可提供保障保证,可以根据所考虑的特定网络的需求量来定制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号