DocumentCode :
3657096
Title :
FloodGuard: A DoS Attack Prevention Extension in Software-Defined Networks
Author :
Haopei Wang;Lei Xu;Guofei Gu
fYear :
2015
fDate :
6/1/2015 12:00:00 AM
Firstpage :
239
Lastpage :
250
Abstract :
This paper addresses one serious SDN-specific attack, i.e., data-to-control plane saturation attack, which overloads the infrastructure of SDN networks. In this attack, an attacker can produce a large amount of table-miss packet_in messages to consume resources in both control plane and data plane. To mitigate this security threat, we introduce an efficient, lightweight and protocol-independent defense framework for SDN networks. Our solution, called FloodGuard, contains two new techniques/modules: proactive flow rule analyzer and packet migration. To preserve network policy enforcement, proactive flow rule analyzer dynamically derives proactive flow rules by reasoning the runtime logic of the SDN/OpenFlow controller and its applications. To protect the controller from being overloaded, packet migration temporarily caches the flooding packets and submits them to the OpenFlow controller using rate limit and round-robin scheduling. We evaluate FloodGuard through a prototype implementation tested in both software and hardware environments. The results show that FloodGuard is effective with adding only minor overhead into the entire SDN/OpenFlow infrastructure.
Keywords :
"Switches","Security","Protocols","Software","IP networks","Throughput"
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks (DSN), 2015 45th Annual IEEE/IFIP International Conference on
Type :
conf
DOI :
10.1109/DSN.2015.27
Filename :
7266854
Link To Document :
بازگشت