AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined Networks
Seungsoo Lee, Seungwon Woo, Jinwoo Kim, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin
Abstract
At the foundation of every network security architecture lies the premise that formulated network flow policies are reliably deployed and enforced by the network infrastructure. However, software-defined networks (SDNs) add a particular challenge to satisfying this premise, as for SDNs the flow pol-icy implementation spans multiple applications and abstraction layers across the SDN stack. In this paper, we focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among these components. This question is rather essential, as when such inconsistencies arise the implications to the security and reliability of the network are devastating. We present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise in OpenFlow networks, the most prevalent SDN protocol used today. We also present results from applying AudiSDN to two widely used SDN controllers, Floodlight and ONOS. In fact, our test results have led to the filing of 3 separate CVE reports. We believe that the approach presented in this paper is applicable to the breadth of OpenFlow platforms used today, and that its broader usage will help to address a serious but yet understudied pragmatic concern.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2a8a5cfe-a8f0-4ae8-bd52-f4ae91fabfe1Cited by top-tier papers1
Ask how each one uses itBuilds on3
- DELTA: A Security Assessment Framework for Software-Defined NetworksSeungsoo Lee, Changhoon Yoon, Chanhee Lee, Seungwon Shin et al.NDSS 2017 · 128 citations
- Attacking the Brain: Races in the SDN Control PlaneLei Xu, Jeff Huang, Sungmin Hong, Jialong Zhang et al.USENIX Security 2017 · 77 citations
- AIM-SDN: Attacking Information Mismanagement in SDN-datastoresVaibhav Hemant Dixit, Adam Doupé, Yan Shoshitaishvili, Ziming Zhao et al.CCS 2018 · 31 citations
Related papers
- SDN Application Backdoor: Disrupting the Service via Poisoning the TopologyShuhua Deng, Xian Qing, Xiaofan Li, Xing Gao et al.INFOCOM 2023 · 8 citations
- Towards Fine-grained Network Security Forensics and Diagnosis in the SDN EraHaopei Wang, Guangliang Yang, Phakpoom Chinprutthiwong, Lei Xu et al.CCS 2018 · 44 citations
- Unexpected Data Dependency Creation and Chaining: A New Attack to SDNFeng Xiao, Jinquan Zhang, Jianwei Huang, Guofei Gu et al.S&P 2020 · 31 citations
- An In-depth Look Into SDN Topology Discovery Mechanisms: Novel Attacks and Practical CountermeasuresEduard Marin, Nicola Bucciol, Mauro ContiCCS 2019 · 60 citations
- When Match Fields Do Not Need to Match: Buffered Packets Hijacking in SDNJiahao Cao, Renjie Xie, Kun Sun, Qi Li et al.NDSS 2020
