• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
成果搜索

author:

Kong, Dezhang (Kong, Dezhang.) [1] | Wu, Chunming (Wu, Chunming.) [2] | Shen, Yi (Shen, Yi.) [3] | Chen, Xiang (Chen, Xiang.) [4] | Liu, Hongyan (Liu, Hongyan.) [5] | Zhang, Dong (Zhang, Dong.) [6]

Indexed by:

EI

Abstract:

One of the most important components of Software-Defined Networking (SDN) is the flow table. It receives flow rules from the controller and uses them to handle network traffic. However, a flow table can only store a few thousand flow rules, which makes it an attractive target for table overflow attacks. These attacks force the controller to populate the flow table with a large number of meaningless flow rules, which prevents normal flows from finding matching rules and therefore having to be reported to the controller. It results in a significant latency overhead, degrading the performance of the whole network. In this paper, we present a key characteristic of table overflow attacks: even though attackers can change some critical attack parameters (e.g., attack speed) to avoid detection, proactive flows from the attacked port always occupy a stable proportion in the flow table regardless of the attack form. In light of this finding, we propose TableGuard, a novel security mechanism that uses the proactive flow rule number as the detection metric and applies a statistical approach to help filter malicious flows. The experiments demonstrate that TableGuard can mitigate both high-rate and low-rate table overflow attacks. Compared with existing defenses, TableGuard has the best mitigation performance and the minimal overhead on normal flows. © 2022 IEEE.

Keyword:

Controllers Software defined networking

Community:

  • [ 1 ] [Kong, Dezhang]Zhejiang University, Hangzhou, China
  • [ 2 ] [Wu, Chunming]Zhejiang University, Hangzhou, China
  • [ 3 ] [Shen, Yi]Zhejiang University, Hangzhou, China
  • [ 4 ] [Chen, Xiang]Zhejiang University, Hangzhou, China
  • [ 5 ] [Liu, Hongyan]Zhejiang University, Hangzhou, China
  • [ 6 ] [Zhang, Dong]Fuzhou University, Fuzhou, China

Reprint 's Address:

Email:

Show more details

Related Keywords:

Related Article:

Source :

Year: 2022

Page: 4167-4172

Language: English

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count: 13

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 0

Online/Total:67/10043960
Address:FZU Library(No.2 Xuyuan Road, Fuzhou, Fujian, PRC Post Code:350116) Contact Us:0591-22865326
Copyright:FZU Library Technical Support:Beijing Aegean Software Co., Ltd. 闽ICP备05005463号-1