DocumentCode :
3762448
Title :
Fingerprinting Software-Defined Networks
Author :
Roberto Bifulco;Heng Cui;Ghassan O. Karame;Felix Klaedtke
Author_Institution :
NEC Labs. Eur., Heidelberg, Germany
fYear :
2015
Firstpage :
453
Lastpage :
459
Abstract :
In this paper, we study the feasibility of fingerprinting of controller-switch interactions in SDN networks by a remote adversary whose aim is to acquire knowledge about specific flow rules that are installed at the switches. This knowledge empowers the adversary with a better understanding of the network´s packet-forwarding logic and exposes the network to a number of threats. In our study, we collect measurements from hosts located across the globe using a realistic SDN network comprising of OpenFlow hardware switches. We show that, by leveraging information from the RTT and packet-pair dispersion of the exchanged packets, fingerprinting attacks on SDN networks succeed with overwhelming probability. We also show that these attacks are not restricted to active adversaries, but can be equally mounted by passive adversaries that only monitor traffic exchanged with the SDN network. Finally, we sketch an efficient countermeasure to strengthen SDN networks against fingerprinting.
Keywords :
"Control systems","Dispersion","Servers","Delays","Probes","Internet","Europe"
Publisher :
ieee
Conference_Titel :
Network Protocols (ICNP), 2015 IEEE 23rd International Conference on
ISSN :
1092-1648
Type :
conf
DOI :
10.1109/ICNP.2015.26
Filename :
7437154
Link To Document :
بازگشت