Software defined networking (SDN) is a new networking paradigm that in recent years has revolutionized network architectures. At its core, SDN separates the data plane, which provides data forwarding functionalities, and the control plane, which implements the network control logic. The separation of these two components provides a virtually centralized point of control in the network, and at the same time abstracts the complexity of the underlying physical infrastructure. Unfortunately, while promising, the SDN approach also introduces new attacks and vulnerabilities. Indeed, previous research shows that, under certain traffic conditions, the required communication between the control and data plane can result in a bottleneck. An attacker can exploit this limitation to mount a new, network-wide, type of denial of service attack, known as the control plane saturation attack. This paper presents LineSwitch, an efficient and effective data plane solution to tackle the control plane saturation attack. LineSwitch employs probabilistic proxying and blacklisting of network traffic to prevent the attack from reaching the control plane, and thus preserve network functionality. We implemented LineSwitch as an extension of the reference SDN implementation, OpenFlow, and run a thorough set of experiments under different traffic and attack scenarios. We compared LineSwitch to the state of the art, and we show that it provides at the same time, the same level of protection against the control plane saturation attack, and a reduced time overhead by up to 30%.

LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined Networking / Ambrosin, Moreno; Conti, Mauro; DE GASPARI, Fabio; Poovendran, Radha. - In: IEEE-ACM TRANSACTIONS ON NETWORKING. - ISSN 1063-6692. - 25:2(2017), pp. 1206-1219. [10.1109/TNET.2016.2626287]

LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined Networking

CONTI, MAURO
;
DE GASPARI, FABIO
;
2017

Abstract

Software defined networking (SDN) is a new networking paradigm that in recent years has revolutionized network architectures. At its core, SDN separates the data plane, which provides data forwarding functionalities, and the control plane, which implements the network control logic. The separation of these two components provides a virtually centralized point of control in the network, and at the same time abstracts the complexity of the underlying physical infrastructure. Unfortunately, while promising, the SDN approach also introduces new attacks and vulnerabilities. Indeed, previous research shows that, under certain traffic conditions, the required communication between the control and data plane can result in a bottleneck. An attacker can exploit this limitation to mount a new, network-wide, type of denial of service attack, known as the control plane saturation attack. This paper presents LineSwitch, an efficient and effective data plane solution to tackle the control plane saturation attack. LineSwitch employs probabilistic proxying and blacklisting of network traffic to prevent the attack from reaching the control plane, and thus preserve network functionality. We implemented LineSwitch as an extension of the reference SDN implementation, OpenFlow, and run a thorough set of experiments under different traffic and attack scenarios. We compared LineSwitch to the state of the art, and we show that it provides at the same time, the same level of protection against the control plane saturation attack, and a reduced time overhead by up to 30%.
2017
Software; Computer Science Applications1707 Computer Vision and Pattern Recognition; Computer Networks and Communications; Electrical and Electronic Engineering
01 Pubblicazione su rivista::01a Articolo in rivista
LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined Networking / Ambrosin, Moreno; Conti, Mauro; DE GASPARI, Fabio; Poovendran, Radha. - In: IEEE-ACM TRANSACTIONS ON NETWORKING. - ISSN 1063-6692. - 25:2(2017), pp. 1206-1219. [10.1109/TNET.2016.2626287]
File allegati a questo prodotto
File Dimensione Formato  
Ambrosin_LineSwitch_2017.pdf

solo gestori archivio

Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 2.17 MB
Formato Adobe PDF
2.17 MB Adobe PDF   Contatta l'autore

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/932900
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 89
  • ???jsp.display-item.citation.isi??? 71
social impact