| 研究生: |
梁祐承 Liang, Yu-Cheng |
|---|---|
| 論文名稱: |
P4 軟體定義網路中新流飽和攻擊之緩解 Mitigation of New-flow Saturation Attacks in P4-based SDN |
| 指導教授: |
蔡孟勳
Tsai, Meng-Hsun |
| 學位類別: |
碩士 Master |
| 系所名稱: |
電機資訊學院 - 資訊工程學系 Department of Computer Science and Information Engineering |
| 論文出版年: | 2021 |
| 畢業學年度: | 109 |
| 語文別: | 英文 |
| 論文頁數: | 37 |
| 中文關鍵詞: | 軟體定義網路 、網路安全 、異常偵測 |
| 外文關鍵詞: | Software-Defined Networks, Network Security, Anomaly Detection |
| 相關次數: | 點閱:131 下載:0 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
隨著網路科技的發展,網路架構管理的彈性愈發重要,軟體定義網路應運而生,為網路服務提供者,虛擬專用伺服器服務提供者與校園網路等等提供了更自由的管理選項。但與此同時,新流飽和攻擊等針對軟體定義網路本身架構所進行的攻擊型態也開始出現。為了解決這類問題,我們分析了相關的作法並提出新方法 SDNSnapshot, 能在緩解此類攻擊的同時確保正常使用者的網路流量不受太大的影響,保持良好的服務品質。
透過模擬實驗,我們證實了此方法的效果,當遭受攻擊時能確保正常使用者封包丟失率在百分之十五以下,而其他相似方法正常使用者封包丟失率約在百分之六十左右,同時兩者對於惡意封包的防禦能力仍在相同水準。
With the growth of the internet, network infrastructure management flexibility has become more and more important, Software-Defined Networks (SDN) enables better network control and management ability for Internet service providers (ISP), Virtual private server (VPS) providers, and campus networks. But there comes some new type of attack against SDN itself, such as new-flow saturation attack. To solve this problem, we analyzed related works and proposed SDNSnapshot, a method can mitigate these type of attack while keep benign traffics not affected.
We prove our work with simulation, when under attack, our method can keep benign drop rate under 15% when related work's benign drop rate is at about 60%, and have the same level of malicious packet blocking performance.
[1] N. McKeown, T. Anderson, H. Balakrishnan, G. Parulkar, L. Peterson, J. Rexford,S. Shenker, and J. Turner, “Openflow: Enabling innovation in campus networks,” SIGCOMM Comput. Commun. Rev., vol. 38, p. 69–74, Mar. 2008.
[2] O. N. Foundation, “P4runtime.” https://github.com/p4lang/p4runtime/releases/tag/v1.3.0, 2020.
[3] “Transmission Control Protocol.” RFC 793, Sept. 1981.
[4] “User Datagram Protocol.” RFC 768, Aug. 1980.
[5] Z. Shelby, K. Hartke, and C. Bormann, “The Constrained Application Protocol(CoAP).” RFC 7252, June 2014.
[6] J. Iyengar and M. Thomson, “QUIC: A UDP-Based Multiplexed and Secure Transport.” RFC 9000, May 2021.
[7] M. Bishop, “Hypertext Transfer Protocol Version 3 (HTTP/3),” Internet-Draft draft-ietf-quic-http-33, Internet Engineering Task Force, 2021. Work in Progress.
[8] J. Xu, L. Wang, and Z. Xu, “An enhanced saturation attack and its mitigation mechanism in software-defined networking,” Computer Networks, vol. 169,p. 107092, 2020.
[9] P. Bosshart, D. Daly, G. Gibb, M. Izzard, N. McKeown, J. Rexford, C. Schlesinger,D. Talayco, A. Vahdat, G. Varghese, and D. Walker, “P4: Programming protocolindependent packet processors,” SIGCOMM Comput. Commun. Rev., vol. 44,p. 87–95, July 2014.
[10] D. J. Heinanen and D. R. Guerin, “A Two Rate Three Color Marker.” RFC 2698,Sept. 1999.
[11] S. Fichera, L. Galluccio, S. C. Grancagnolo, G. Morabito, and S. Palazzo, “Operetta: An openflow-based remedy to mitigate tcp synflood attacks against webservers,” Computer Networks, vol. 92, pp. 89–100, 2015.
[12] R. Mohammadi, R. Javidan, and M. Conti, “Slicots: An sdn-based lightweightcountermeasure for tcp syn flooding attacks,” IEEE Transactions on Network and Service Management, vol. 14, no. 2, pp. 487–497, 2017.
[13] W. Eddy, “TCP SYN Flooding Attacks and Common Mitigations.” RFC 4987,Aug. 2007.
[14] R. R. Kompella, S. Singh, and G. Varghese, “On scalable attack detection in the network,” in Proceedings of the 4th ACM SIGCOMM Conference on Internet Measurement, IMC ’04, (New York, NY, USA), p. 187–200, Association for Computing Machinery, 2004.
[15] S. Shin, V. Yegneswaran, P. Porras, and G. Gu, “Avant-guard: Scalable and vigilant switch flow management in software-defined networks,” in Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security, CCS’13, (New York, NY, USA), p. 413–424, Association for Computing Machinery,2013.
[16] F. Zhang, J. Geng, Z. Qin, and M. Zhou, “Detecting the ddos attacks based on syn proxy and hop-count filter,” in 2007 International Conference on Communications, Circuits and Systems, pp. 457–461, 2007.
[17] L. Wei and C. Fung, “Flowranger: A request prioritizing algorithm for controller dos attacks in software defined networks,” in 2015 IEEE International Conference on Communications (ICC), pp. 5254–5259, 2015.
[18] M. A. Sarwar, M. Hussain, M. U. Anwar, and M. Ahmad, “Flowjustifier: An optimized trust-based request prioritization approach for mitigation of sdn controller ddos attacks in the iot paradigm,” in Proceedings of the 3rd International Conference on Future Networks and Distributed Systems, ICFNDS ’19, (New York, NY, USA), Association for Computing Machinery, 2019.
[19] G. Shang, P. Zhe, X. Bin, H. Aiqun, and R. Kui, “Flooddefender: Protecting data and control plane resources under sdn-aimed dos attacks,” in IEEE INFOCOM 2017 - IEEE Conference on Computer Communications, pp. 1–9, 2017.
[20] H. Wang, L. Xu, and G. Gu, “Floodguard: A dos attack prevention extension in software-defined networks,” in 2015 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, pp. 239–250, 2015.
[21] A. Ruia, C. J. Casey, S. Saha, and A. Sprintson, “Flowcache: A cache-based approach for improving sdn scalability,” in 2016 IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), pp. 610–615, 2016.
[22] C. E. Shannon, “A mathematical theory of communication,” The Bell System Technical Journal, vol. 27, no. 3, pp. 379–423, 1948.
[23] J. v. Brakel, “Robust peak detection algorithm using zscores.” https://stackoverflow.com/questions/22583391/peak-signal-detection-in-realtime-timeseries-data/22640362#22640362, 2014.
[24] P. Bosshart, G. Gibb, H.-S. Kim, G. Varghese, N. McKeown, M. Izzard, F. Mujica, and M. Horowitz, “Forwarding metamorphosis: Fast programmable match-action processing in hardware for sdn,” in Proceedings of the ACM SIGCOMM 2013 Conference on SIGCOMM, SIGCOMM ’13, (New York, NY, USA), p. 99–110, Association for Computing Machinery, 2013.
[25] M. Mitzenmacher, Bloom Filters, pp. 252–255. Boston, MA: Springer US, 2009.
[26] P. Bose, H. Guo, E. Kranakis, A. Maheshwari, P. Morin, J. Morrison, M. Smid, and Y. Tang, “On the false-positive rate of bloom filters,” Information Processing Letters, vol. 108, no. 4, pp. 210–213, 2008.
[27] K. Christensen, A. Roginsky, and M. Jimeno, “A new analysis of the false positive rate of a bloom filter,” Information Processing Letters, vol. 110, no. 21, pp. 944–949, 2010.
[28] T. P. A. W. Group, “P416 portable switch architecture (psa).” https://p4lang.github.io/p4-spec/docs/PSA.pdf, 4 2021.
[29] G. C. M. Moura, C. Ga˜n´an, Q. Lone, P. Poursaied, H. Asghari, and M. van Eeten, “How dynamic is the isps address space? towards internet-wide dhcp churn estimation,” in 2015 IFIP Networking Conference (IFIP Networking), pp. 1–9, 2015.
[30] M. Ring, S. Wunderlich, D. Gr¨udl, D. Landes, and A. Hotho, “Flow-based benchmark data sets for intrusion detection,” in Proceedings of the 16th European Conference on Cyber Warfare and Security (ECCWS), pp. 361–369, ACPI, 2017.
[31] M. Ring, S. Wunderlich, D. Gr¨udl, D. Landes, and A. Hotho, “Creation of flowbased data sets for intrusion detection,” Journal of Information Warfare, vol. 16, pp. 40–53, 2017.
[32] O. N. Foundation, “Behavioral model (bmv2).” https://github.com/p4lang/behavioral-model/releases/tag/1.14.0, 2020.
[33] A. Sivaraman, M. Budiu, A. Cheung, C. Kim, S. Licking, G. Varghese, H. Balakrishnan, M. Alizadeh, and N. McKeown, “Packet transactions: A programming model for data-plane algorithms at hardware speed,” 12 2015.