Amplified Distributed Denial of Service Attack in Software Defined Networking

Software Defined Networking (SDN) is an alternative networking paradigm that provides flexible network management through the separation between data plane and control plane functionalities. This separation results in extensive communication between control and data plane, which can result in a severe bottleneck for the whole network, under high traffic conditions. Moreover, researchers shown that an adversary can exploit this bottleneck to mount a powerful Denial of Service attack on the control plane, known as Control Plane Saturation Attack (CPSA). In this paper, we provide a thorough analysis of the CPSA, and in particular we show how it can be amplified by long forwarding paths in an SDN network. We prove the effectiveness of the attack through extensive testing using OpenFlow, the most widely adopted control-data plane communication protocol for SDN. Our evaluation shows that, when the forwarding path length in increased by 5 times, the attacker can leverage a 55% decrease in the attack rate required to incapacitate the network.

[1]  Mauro Conti,et al.  LineSwitch: Efficiently Managing Switch Flow in Software-Defined Networking while Effectively Tackling DoS Attacks , 2015, AsiaCCS.

[2]  Rodrigo Braga,et al.  Lightweight DDoS flooding attack detection using NOX/OpenFlow , 2010, IEEE Local Computer Network Conference.

[3]  Martín Casado,et al.  The Design and Implementation of Open vSwitch , 2015, NSDI.

[4]  Vitaly Shmatikov,et al.  dFence: Transparent Network-based Denial of Service Mitigation , 2007, NSDI.

[5]  Peter Reiher,et al.  Drawbridge: software-defined DDoS-resistant traffic engineering , 2015, SIGCOMM 2015.

[6]  Lei Xu,et al.  FloodGuard: A DoS Attack Prevention Extension in Software-Defined Networks , 2015, 2015 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks.

[7]  Fernando M. V. Ramos,et al.  Towards secure and dependable software-defined networks , 2013, HotSDN '13.

[8]  Vinod Yegneswaran,et al.  AVANT-GUARD: scalable and vigilant switch flow management in software-defined networks , 2013, CCS.

[9]  Kotagiri Ramamohanarao,et al.  Survey of network-based defense mechanisms countering the DoS and DDoS problems , 2007, CSUR.

[10]  Nick McKeown,et al.  OpenFlow: enabling innovation in campus networks , 2008, CCRV.

[11]  Mauro Conti,et al.  LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined Networking , 2017, IEEE/ACM Transactions on Networking.

[12]  Jun Li,et al.  Drawbridge: software-defined DDoS-resistant traffic engineering , 2014, SIGCOMM.

[13]  Paul Smith,et al.  OpenFlow: A security analysis , 2013, 2013 21st IEEE International Conference on Network Protocols (ICNP).