Abstract
Using Software-defined Networks in wide area (SDN-WAN) has been strongly emerging in the past years. Due to scalability and economical reasons, SDN-WAN mostly uses an in-band control mechanism, which implies that control and data sharing the same critical physical links. However, the in-band control and centralized control architecture can be exploited by attackers to launch distributed denial of service (DDoS) on SDN control plane by flooding the shared links and/or the Open flow agents. Therefore, constructing a resilient software designed network requires dynamic isolation and distribution of the control flow to minimize damage and significantly increase attack cost. Existing solutions fall short to address this challenge because they require expensive extra dedicated resources or changes in OpenFlow protocol. In this paper, we propose a moving target technique called REsilient COntrol Network architecture (ReCON) that uses the same SDN network resources to defend SDN control plane dynamically against the DDoS attacks. ReCON essentially, (1) minimizes the sharing of critical resources among data and control traffic, and (2) elastically increases the limited capacity of the software control agents on-demand by dynamically using the under-utilized resources from within the same SDN network. To implement a practical solution, we formalize ReCON as a constraints satisfaction problem using Satisfiability Modulo Theory (SMT) to guarantee a correct-by-construction control plan placement that can handle dynamic network conditions.
| Original language | English |
|---|---|
| Title of host publication | MTD 2018 - Proceedings of the 5th ACM Workshop on Moving Target Defense, co-located with CCS 2018 |
| Publisher | Association for Computing Machinery |
| Pages | 80-89 |
| Number of pages | 10 |
| ISBN (Electronic) | 9781450360036 |
| DOIs | |
| State | Published - 15 Oct 2018 |
| Externally published | Yes |
| Event | 5th ACM Workshop on Moving Target Defense, MTD 2018, held in conjunction with the 25th ACM Conference on Computer and Communications Security, ACM CCS 2018 - Toronto, Canada Duration: 15 Oct 2018 → … |
Publication series
| Name | Proceedings of the ACM Conference on Computer and Communications Security |
|---|---|
| ISSN (Print) | 1543-7221 |
Conference
| Conference | 5th ACM Workshop on Moving Target Defense, MTD 2018, held in conjunction with the 25th ACM Conference on Computer and Communications Security, ACM CCS 2018 |
|---|---|
| Country/Territory | Canada |
| City | Toronto |
| Period | 15/10/18 → … |
Bibliographical note
Publisher Copyright:© 2018 Association for Computing Machinery.
ASJC Scopus subject areas
- Software
- Computer Networks and Communications