White Box Analysis at the Service of Low Rate Saturation Attacks on Virtual SDN Data Plane
Title | White Box Analysis at the Service of Low Rate Saturation Attacks on Virtual SDN Data Plane |
Publication Type | Conference Paper |
Year of Publication | 2019 |
Authors | Khorsandroo, Sajad, Tosun, Ali Saman |
Conference Name | 2019 IEEE 44th LCN Symposium on Emerging Topics in Networking (LCN Symposium) |
ISBN Number | 978-1-7281-2561-9 |
Keywords | cloud computing, cloud data center, composability, compositionality, computer centres, computer network security, dynamic code analysis techniques, effective low profile attacks, legacy network protocols, low rate saturation attack, low rate saturation attacks, Metrics, OpenFlow communication protocol, programmable virtual switches, Protocols, pubcrawl, resilience, Resiliency, SDN, security, software defined networking, software switch functionalities, static code analysis techniques, virtual SDN data plane, Virtual Switch, Virtual Switches, virtualisation, white box analysis, White Box Security |
Abstract | Today's virtual switches not only support legacy network protocols and standard network management interfaces, but also become adapted to OpenFlow as a prevailing communication protocol. This makes them a core networking component of today's virtualized infrastructures which are able to handle sophisticated networking scenarios in a flexible and software-defined manner. At the same time, these virtual SDN data planes become high-value targets because a compromised switch is hard to detect while it affects all components of a virtualized/SDN-based environment.Most of the well known programmable virtual switches in the market are open source which makes them cost-effective and yet highly configurable options in any network infrastructure deployment. However, this comes at a cost which needs to be addressed. Accordingly, this paper raises an alarm on how attackers may leverage white box analysis of software switch functionalities to lunch effective low profile attacks against it. In particular, we practically present how attackers can systematically take advantage of static and dynamic code analysis techniques to lunch a low rate saturation attack on virtual SDN data plane in a cloud data center. |
URL | https://ieeexplore.ieee.org/document/9000660/ |
DOI | 10.1109/LCNSymposium47956.2019.9000660 |
Citation Key | khorsandroo_white_2019 |
- Protocols
- White Box Security
- white box analysis
- virtualisation
- Virtual Switches
- Virtual Switch
- virtual SDN data plane
- static code analysis techniques
- software switch functionalities
- software defined networking
- security
- SDN
- Resiliency
- resilience
- pubcrawl
- Cloud Computing
- programmable virtual switches
- OpenFlow communication protocol
- Metrics
- low rate saturation attacks
- low rate saturation attack
- legacy network protocols
- effective low profile attacks
- dynamic code analysis techniques
- computer network security
- computer centres
- Compositionality
- composability
- cloud data center