Affiliation:
1. PLA Strategic Support Force Information Engineering University, Zhengzhou, China
2. National Digital Switching System Engineering and Technological Research Center, Zhengzhou, China
Abstract
Software-defined networking (SDN) decouples the control plane from the data plane, which increases network flexibility and programmability. However, the “three-layer two-interface” architecture of SDN introduces new security issues. Attackers can collect fingerprint information (such as network types, controller types, and critical flow rules) by analyzing round-trip time (RTT) distribution of test packets. In order to defend against the fingerprint attack with limited attack time, we first design a probabilistic scrambling strategy. This strategy not only interferes with the delay distribution of probe packets in attack flow but also reduces the negative impact on the performance of legal packets in normal flow. However, if fingerprint attackers have unlimited attack time, it is not enough to defend against the attack only by this strategy. Therefore, we further propose a controller dynamic scheduling strategy to change SDN fingerprint information actively. Because scheduling different types of controllers to work in different periods will generate costs, the scheduling strategy is also responsible for determining the optimal switching time point to balance security benefits and costs. At last, we implement the defense mechanism on different types of controllers and verify its effectiveness in experimental scenarios. The experimental results show that the mechanism can effectively hide the SDN fingerprint information while reducing the negative impact on network performance.
Funder
National Key Research and Development Program of China
Subject
Computer Networks and Communications,Information Systems
Reference28 articles.
1. OpenFlow
2. Security in SDN: a comprehensive survey;J. C. C. Chica;Journal of Network and Computer Applications,2020
3. A comprehensive survey of security threats and their mitigation techniques for next-generation SDN controllers;T. Han;Concurrency and Computation Practice and Experience,2019
4. Remote Physical Device Fingerprinting
5. SinFP, unification of active and passive operating system fingerprinting
Cited by
4 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献