Manipulating Sensitive Match Fields to Poison Applications in SDN

Shuhua Deng, Lihui Chen, Xieping Gao · IEEE Transactions on Network and Service Management · 2023

Software-Defined Networking (SDN) significantly simplifies the management of networks by deploying various applications. However, the performance gap between the application and the forwarding device brings new security concerns for the network. In this paper, we systematically study the match field defined in the OpenFlow protocol and reveal the vulnerability in the match process of data streams. Then, we propose sensitive field manipulation attacks to saturate the network bottleneck. Furthermore, we investigate the threats to SDN architecture by exploiting such attacks. We demonstrate the feasibility of the attack and evaluate it in a physical environment. To defend against such attacks, we design SFieldDefender to detect malicious probing by training machine learning models. Moreover, we design a multi-policy coordination mechanism to deal with different types of abnormal traffic. Implementations and evaluations demonstrate that SFieldDefender can effectively detect the sensitive field manipulation attack and protect the network core services.

Read the paper · More papers on PaperTik