A New Colluded Adversarial VNet Embeddings Attack in Cloud

I‐Hsien Liu, Tay-Jiun Fang, Jung-Shian Li, Mengwei Sun, Chuan-Gang Liu · 2017

Nowadays, network virtualization has been widely investigated in order to prevent Internet ossification, and develop future emerging network applications flexibly. However, prior work by Pignolet et al. shows the possible attacking methodology with which the attackers can disclose the whole cloud topology while deploying virtual networks in cloud named “Topology Disclosure Attack”. In this attack model, the attacker pretends to deploy virtual networks in cloud by issuing the graph requests to service provider. And the service provider responds the requests to the attacker after examining his/her topology resources. With this request/reply model, Pignolet et al. believe this attack eventually infers the targeted topology. However, one vital reason leads this attack to the failure- too many virtual requests from one adversary in a time. This paper tries to provide a new topology disclosure attack model, which multiple attackers launch attacks at the same time with the assistance of proposed Query-Trie and network tomography technique. Hence, in this paper, we propose much more possible attack model in cloud and this topic also encourages the network researchers to develop resistance mechanism against it in the future.

Read the paper · More papers on PaperTik