Fleet: defending SDNs from malicious administrators

S. Matsumoto, Samuel Hitz, A. Perrig
{"title":"Fleet: defending SDNs from malicious administrators","authors":"S. Matsumoto, Samuel Hitz, A. Perrig","doi":"10.1145/2620728.2620750","DOIUrl":null,"url":null,"abstract":"We present the malicious administrator problem, in which one or more network administrators attempt to damage routing, forwarding, or network availability by misconfiguring controllers. While this threat vector has been acknowledged in previous work, most solutions have focused on enforcing specific policies for forwarding rules. We present a definition of this problem and a controller design called Fleet that makes a first step towards addressing this problem. We present two protocols that can be used with the Fleet controller, and argue that its lower layer deployed on top of switches eliminates many problems of using multiple controllers in SDNs. We then present a prototype simulation and show that as long as a majority of non-malicious administrators exists, we can usually recover from link failures within several seconds (a time dominated by failure detection speed and inter-administrator latency).","PeriodicalId":309136,"journal":{"name":"Proceedings of the third workshop on Hot topics in software defined networking","volume":"25 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-08-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"71","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the third workshop on Hot topics in software defined networking","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2620728.2620750","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 71

Abstract

We present the malicious administrator problem, in which one or more network administrators attempt to damage routing, forwarding, or network availability by misconfiguring controllers. While this threat vector has been acknowledged in previous work, most solutions have focused on enforcing specific policies for forwarding rules. We present a definition of this problem and a controller design called Fleet that makes a first step towards addressing this problem. We present two protocols that can be used with the Fleet controller, and argue that its lower layer deployed on top of switches eliminates many problems of using multiple controllers in SDNs. We then present a prototype simulation and show that as long as a majority of non-malicious administrators exists, we can usually recover from link failures within several seconds (a time dominated by failure detection speed and inter-administrator latency).
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Fleet:防御恶意管理员攻击sdn
我们提出了恶意管理员问题,其中一个或多个网络管理员试图通过错误配置控制器来破坏路由、转发或网络可用性。虽然在以前的工作中已经承认了这种威胁向量,但大多数解决方案都集中在执行转发规则的特定策略上。我们给出了这个问题的定义,并设计了一个名为Fleet的控制器,这是解决这个问题的第一步。我们提出了两种可与Fleet控制器一起使用的协议,并认为其部署在交换机顶部的下层消除了在sdn中使用多个控制器的许多问题。然后,我们展示了一个原型模拟,并表明只要存在大多数非恶意管理员,我们通常可以在几秒钟内从链路故障中恢复过来(这一时间由故障检测速度和管理员间延迟决定)。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Enabling layer 2 pathlet tracing through context encoding in software-defined networking ReversePTP: a software defined networking approach to clock synchronization Flow-based load balancing in multipathed layer-2 networks using OpenFlow and multipath-TCP Fleet: defending SDNs from malicious administrators Don't call them middleboxes, call them middlepipes
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1