arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.14805cs.NIcs.CR

重新思考软件定义网络中的链路发现:动态随机化方法

Rethinking Software-Defined Networking Link Discovery with Dynamic Randomization

Mingming Chen, Teryl Taylor, Frederico Araujo, Benjamin E. Ujcich, Thomas La Porta, Trent Jaeger

首次发表
浏览论文内容

中文总结 AI 辅助

针对SDN链路发现易受伪造攻击的问题,提出动态随机化协议ChameleonDisc,通过消除静态LLDP签名并采用移动目标防御,有效预防和检测拓扑投毒,在OpenDaylight上验证了其安全性与性能的可调权衡。

中文摘要 AI 辅助

软件定义网络(SDN)将控制平面与数据平面分离,实现了可编程的集中式网络管理。SDN的一项核心服务是拓扑发现——一个周期性地识别网络链路的过程。然而,我们对五个开源SDN控制器和十种发现协议的分析表明,它们仍然容易受到至少一种形式的链路伪造攻击。其共同的根源在于它们依赖传统的链路层发现协议(LLDP)数据包,这些数据包的静态标识符暴露了其发现目的,并吸引攻击者对其进行利用。我们提出了ChameleonDisc,一种动态链路发现协议,通过消除这一根源来同时预防和检测拓扑投毒攻击。我们的关键见解是,SDN控制器可以在不向发现数据包中嵌入有意义信息的情况下推断拓扑。ChameleonDisc移除了可被攻击的静态LLDP签名,并采用了一种移动目标防御,该防御结合了诱饵、混淆和伪装技术,在运行时动态实例化,以预防拓扑投毒并检测操纵行为。我们在OpenDaylight上实现了ChameleonDisc,并证明其对所有基于标识符的拓扑投毒攻击均有效。在252条链路的拓扑中,合法链路变化的中位收敛时间为1.37–4.53秒,恶意中继检测的中位时间为4.06秒,平均CPU额外增加13.0个百分点,保留堆差异可忽略不计。在多达816条链路的拓扑中,ChameleonDisc提供了可调的安全-性能权衡;扩大发现间隔会减少CPU和映射状态,但代价是增加攻击检测延迟。

英文摘要

Software-defined networking (SDN) separates the control and data planes, enabling programmable, centralized network management. A core SDN service is topology discovery --- a periodic process that identifies network links. However, our analysis of five open-source SDN controllers and ten discovery protocols shows that all remain vulnerable to at least one form of link-fabrication attack. The common root cause is their reliance on traditional Link Layer Discovery Protocol (LLDP) packets, whose static identifiers expose their discovery purpose and attract adversaries to exploit them. We propose ChameleonDisc, a dynamic link-discovery protocol that simultaneously prevents and detects topology-poisoning attacks by eliminating this root cause. Our key insight is that an SDN controller can infer topology without embedding meaningful information in discovery packets. ChameleonDisc removes targetable static LLDP signatures and employs a moving-target defense that combines decoy, obfuscation, and camouflage techniques instantiated dynamically at runtime to prevent topology poisoning and detect manipulation. We implement ChameleonDisc on OpenDaylight and demonstrate effectiveness against all identifier-based topology-poisoning attacks. On a 252-link topology, median convergence is 1.37--4.53\,s for legitimate link changes and 4.06\,s for malicious relay detection, with 13.0 percentage points of additional mean CPU and negligible retained-heap difference. Across topologies up to 816 links, ChameleonDisc provides a tunable security--performance trade-off; expanding discovery intervals reduces CPU and mapping state at the cost of increased attack-detection latency.

发表机构

  • University of Texas at Dallas(德克萨斯大学达拉斯分校)
  • IBM Research(IBM 研究院)
  • Georgetown University(乔治城大学)
  • The Pennsylvania State University(宾夕法尼亚州立大学)
  • University of California, Riverside(加利福尼亚大学河滨分校)

机构由 AI 辅助整理,请以论文原文为准。

↑