Visible to the public White Box Analysis at the Service of Low Rate Saturation Attacks on Virtual SDN Data Plane

TitleWhite Box Analysis at the Service of Low Rate Saturation Attacks on Virtual SDN Data Plane
Publication TypeConference Paper
Year of Publication2019
AuthorsKhorsandroo, Sajad, Tosun, Ali Saman
Conference Name2019 IEEE 44th LCN Symposium on Emerging Topics in Networking (LCN Symposium)
ISBN Number978-1-7281-2561-9
Keywordscloud computing, cloud data center, composability, compositionality, computer centres, computer network security, dynamic code analysis techniques, effective low profile attacks, legacy network protocols, low rate saturation attack, low rate saturation attacks, Metrics, OpenFlow communication protocol, programmable virtual switches, Protocols, pubcrawl, resilience, Resiliency, SDN, security, software defined networking, software switch functionalities, static code analysis techniques, virtual SDN data plane, Virtual Switch, Virtual Switches, virtualisation, white box analysis, White Box Security
Abstract

Today's virtual switches not only support legacy network protocols and standard network management interfaces, but also become adapted to OpenFlow as a prevailing communication protocol. This makes them a core networking component of today's virtualized infrastructures which are able to handle sophisticated networking scenarios in a flexible and software-defined manner. At the same time, these virtual SDN data planes become high-value targets because a compromised switch is hard to detect while it affects all components of a virtualized/SDN-based environment.Most of the well known programmable virtual switches in the market are open source which makes them cost-effective and yet highly configurable options in any network infrastructure deployment. However, this comes at a cost which needs to be addressed. Accordingly, this paper raises an alarm on how attackers may leverage white box analysis of software switch functionalities to lunch effective low profile attacks against it. In particular, we practically present how attackers can systematically take advantage of static and dynamic code analysis techniques to lunch a low rate saturation attack on virtual SDN data plane in a cloud data center.

URLhttps://ieeexplore.ieee.org/document/9000660/
DOI10.1109/LCNSymposium47956.2019.9000660
Citation Keykhorsandroo_white_2019