Combat-Sniff: A Comprehensive Countermeasure to Resist Data Plane Eavesdropping in Software-Defined Networks

Fan Jiang · American Journal of Networks and Communications · 2016

Software-defined networking (SDN), on account of its unprecedented capability of network traffic monitoring and data resource transferring, has been deployed into a wide range of application scenarios. However, typical cyber-attacks which prevail in traditional IP networks, have also mutated their implementation models adjusting to SDN environment. Eavesdropping is one of such attacks and causes severe information disclosure to different degree. In this paper, we focus on data plane eavesdropping in SDN and treat it on two levels according to the extent an adversarial sniffer can exploit a SDN switch. Then we introduce Combat-Sniff, a comprehensive countermeasure which includes two methods to deal with the two-level sniffing respectively. And later, we both theoretically and experimentally demonstrate their reliability and performance. Results represent that we can exert Combat-Sniff in SDN to satisfy different security requirements with an acceptable overhead.

Read the paper · More papers on PaperTik