论文标题

加强SDN安全性:协议方言和降级攻击

Strengthening SDN Security: Protocol Dialecting and Downgrade Attacks

论文作者

Sjoholmsierchio, Michael, Hale, Britta, Lukaszewski, Daniel, Xie, Geoffrey G.

论文摘要

软件定义的网络(SDN)已成为数据中心和5G网络的基本技术。在SDN网络中,路由和流量管理决策由集中式控制器做出,并通过控制渠道传达给交换机。已提出了运输层安全性(TLS)作为单个安全层。但是,TLS的使用是可选的,连接仍然容易受到降级攻击的影响。在本文中,我们建议使用协议方言方法来加强安全保证,以提供其他可自定义的安全性。我们考虑并评估了两种用于OpenFlow协议操作的方言方法,并将单独的身份验证添加到独立于TLS的SDN控制通道中,并在TLS实现的可选情况下为降级攻击提供了鲁棒性。此外,我们测量了在Mininet实验中使用这些方言原语的性能影响。结果表明,通信潜伏期不到22%。

Software-defined networking (SDN) has become a fundamental technology for data centers and 5G networks. In an SDN network, routing and traffic management decisions are made by a centralized controller and communicated to switches via a control channel. Transport Layer Security (TLS) has been proposed as its single security layer; however, use of TLS is optional and connections are still vulnerable to downgrade attacks. In this paper, we propose the strengthening of security assurance using a protocol dialecting approach to provide additional and customizable security. We consider and evaluate two dialecting approaches for OpenFlow protocol operation, adding per-message authentication to the SDN control channel that is independent of TLS and provides robustness against downgrade attacks in the optional case of TLS implementation. Furthermore, we measure the performance impact of using these dialecting primitives in a Mininet experiment. The results show a modest increase of communication latency of less than 22%.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源