IA-DD: An SDN Topological Poisoning Attack Defense Scheme Based on Blockchain
Bin Gu, Xingwei Wang, Kaiqi Yang, Yu Wang, Qiang He · 2022
Software defined networking (SDN) have the advan-tages of centralized control, global visibility, and programmabil-ity, but these features also bring new security issues, such as Topological Poisoning Attack (TPA), where attackers can attack topology discovery services by stealing host locations or forging link information. Considering the three levels of identity, data package and path, this paper designs a chain authentication defense scheme. The scheme includes authentication mechanism, transaction information storage mechanism, source IP authenti-cation mechanism and smart contract notification mechanism. The received packets are authenticated by digital signature algorithm, and the trusted identity and location information are stored securely. At the same time, an improved block storage structure is designed to avoid data redundancy, and malicious information is processed by smart contract notification and stream rule installation. The experimental results show that the defense scheme designed in this paper can effectively defend against TPA attacks. Compared with the benchmark mechanism, the deployment of this scheme has less impact on controller performance and less impact on the delay of topology discovery in SDN.