首页> 外文期刊>IEEE/ACM Transactions on Networking >LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined Networking
【24h】

LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined Networking

机译:LineSwitch:解决软件定义网络中的控制平面饱和攻击

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Software defined networking (SDN) is a new networking paradigm that in recent years has revolutionized network architectures. At its core, SDN separates the data plane, which provides data forwarding functionalities, and the control plane, which implements the network control logic. The separation of these two components provides a virtually centralized point of control in the network, and at the same time abstracts the complexity of the underlying physical infrastructure. Unfortunately, while promising, the SDN approach also introduces new attacks and vulnerabilities. Indeed, previous research shows that, under certain traffic conditions, the required communication between the control and data plane can result in a bottleneck. An attacker can exploit this limitation to mount a new, network-wide, type of denial of service attack, known as the control plane saturation attack. This paper presents LineSwitch, an efficient and effective data plane solution to tackle the control plane saturation attack. LineSwitch employs probabilistic proxying and blacklisting of network traffic to prevent the attack from reaching the control plane, and thus preserve network functionality. We implemented LineSwitch as an extension of the reference SDN implementation, OpenFlow, and run a thorough set of experiments under different traffic and attack scenarios. We compared LineSwitch to the state of the art, and we show that it provides at the same time, the same level of protection against the control plane saturation attack, and a reduced time overhead by up to 30%.
机译:软件定义网络(SDN)是一种新的网络范例,近年来已经彻底改变了网络体系结构。 SDN的核心是将提供数据转发功能的数据平面与实现网络控制逻辑的控制平面分开。这两个组件的分离提供了网络中虚拟的集中控制点,同时抽象了基础物理基础架构的复杂性。不幸的是,尽管有希望,但SDN方法还引入了新的攻击和漏洞。实际上,先前的研究表明,在某些流量条件下,控制平面和数据平面之间所需的通信可能会导致瓶颈。攻击者可以利用此限制来发起一种新的,全网络范围的拒绝服务攻击类型,称为控制平面饱和攻击。本文介绍了LineSwitch,这是一种有效且有效的数据平面解决方案,可解决控制平面饱和攻击。 LineSwitch利用网络流量的概率代理和黑名单来防止攻击到达控制平面,从而保留网络功能。我们将LineSwitch实施为参考SDN实施OpenFlow的扩展,并在不同的流量和攻击情形下进行了全面的实验。我们将LineSwitch与最新技术进行了比较,结果表明LineSwitch同时提供了相同的保护级别,以抵制控制平面饱和攻击,并减少了高达30%的时间开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号