Software Defined Networking (SDN) introduces a new communication network management paradigm and has gained much attention from academia and industry. However, the centralized nature of SDN is a potential vulnerability to the system since attackers may launch denial of services (DoS) attacks against the controller. Existing solutions limit requests rate to the controller by dropping overflowed requests, but they also drop legitimate requests to the controller. To address this problem, we propose FlowRanger, a buffer prioritizing solution for controllers to handle routing requests based on their likelihood to be attacking requests, which derives the trust values of the requesting sources. Based on their trust values, FlowRanger classifies routing requests into multiple buffer queues with different priorities. Thus, attacking requests are served with a lower priority than regular requests. Our simulation results demonstrates that FlowRanger can significantly enhance the request serving rate of regular users under DoS attacks against the controller. To the best of our knowledge, our work is the first solution to battle against controller DoS attacks on the controller side.
[1]
Kevin Benton,et al.
OpenFlow vulnerability assessment
,
2013,
HotSDN '13.
[2]
Lei Xu,et al.
FloodGuard: A DoS Attack Prevention Extension in Software-Defined Networks
,
2015,
2015 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks.
[3]
Mabry Tyson,et al.
FRESCO: Modular Composable Security Services for Software-Defined Networks
,
2013,
NDSS.
[4]
Vinod Yegneswaran,et al.
AVANT-GUARD: scalable and vigilant switch flow management in software-defined networks
,
2013,
CCS.
[5]
Fernando M. V. Ramos,et al.
Towards secure and dependable software-defined networks
,
2013,
HotSDN '13.
[6]
Nick McKeown,et al.
OpenFlow: enabling innovation in campus networks
,
2008,
CCRV.
[7]
Brighten Godfrey,et al.
VeriFlow: verifying network-wide invariants in real time
,
2012,
HotSDN '12.
[8]
Guofei Gu,et al.
Attacking software-defined networks: a first feasibility study
,
2013,
HotSDN '13.