Swguard: Mitigating Flow Rule Modification Attack in P4 Switches

Lilima Jain, U. Venkanna · 2023

A Flow table is used to process the packets in P4 switches. The Flow table in P4 switches is prone to attacks, which leads to poor packet processing behavior and network monitoring. Unfortunately, runtime verification of Flow rule modification in a network is a challenging task. This letter proposes, SwGuard: a P4-driven solution for Flow rule modification attack detection and mitigation mechanism in a switch. Typically, SwGuard keeps track of the packet_in request sent to the controller to detect and mitigate the attack by blocking the attacker’s interface. Our solution was implemented using BMv2 switches, improved the packet dropping rate to 70%, and reduced the controller overhead by 31.4%.

Read the paper · More papers on PaperTik