USENIX Security2018Top-tier venue
NetHide: Secure and Practical Network Topology Obfuscation
Roland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever, Martin T. Vechev
Abstract
Simple path tracing tools such as traceroute allow malicious users to infer network topologies remotely and use that knowledge to craft advanced denial-of-service (DoS) attacks such as Link-Flooding Attacks (LFAs). Yet, despite the risk, most network operators still allow path tracing as it is an essential network debugging tool. In this paper, we present NetHide, a network topology obfuscation framework that mitigates LFAs while preserving the practicality of path tracing tools. The key idea behind NetHide is to formulate network obfuscation as a multi-objective optimization problem that allows for a flexible tradeoff between security (encoded as hard constraints) and usability (encoded as soft constraints). While solving this problem exactly is hard, we show that NetHide can obfuscate topologies at scale by only considering a subset of the candidate solutions and without reducing obfuscation quality. In practice, NetHide obfuscates the topology by intercepting and modifying path tracing probes directly in the data plane. We show that this process can be done at line-rate, in a stateless fashion, by leveraging the latest generation of programmable network devices. We fully implemented NetHide and evaluated it on realistic topologies. Our results show that NetHide is able to obfuscate large topologies (> 150 nodes) while preserving near-perfect debugging capabilities. In particular, we show that operators can still precisely trace back > 90 % of link failures despite obfuscation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers20
- ICARUS: Attacking low Earth orbit satellite networksGiacomo Giuliari, Tommaso Ciussani, Adrian Perrig, Ankit SinglaUSENIX ATC 2021 · 99 citations
- On the Feasibility of Rerouting-Based DDoS DefensesMuoi Tran, Min Suk Kang, Hsu-Chun Hsiao, Wei-Hsuan Chiang et al.S&P 2019 · 39 citations
- DeeP4R: Deep Packet Inspection in P4 using Packet RecirculationSahil Gupta, Devashish Gosain, Minseok Kwon, Hrishikesh B. AcharyaINFOCOM 2023 · 24 citations
- IMap: Fast and Scalable In-Network Scanning with Programmable SwitchesGuanyu Li, Menghao Zhang, Cheng Guo, Han Bao et al.NSDI 2022 · 14 citations
- Enhancing Network Attack Detection with Distributed and In-Network Data Collection SystemSeyed Mohammad Mehdi Mirnajafizadeh, Ashwin Raam Sethuram, David Mohaisen, DaeHun Nyang et al.USENIX Security 2024 · 12 citations
Builds on3
- SPIFFY: Inducing Cost-Detectability Tradeoffs for Persistent Link-Flooding AttacksMin Suk Kang, Virgil D. Gligor, Vyas SekarNDSS 2016 · 123 citations
- Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP RoutingJared M. Smith, Max SchuchardS&P 2018 · 71 citations
- SIBRA: Scalable Internet Bandwidth Reservation ArchitectureCristina Basescu, Raphael M. Reischuk, Pawel Szalachowski, Adrian Perrig et al.NDSS 2016 · 61 citations
Related papers
- EqualNet: A Secure and Practical Defense for Long-term Network Topology ObfuscationJinwoo Kim, Eduard Marin, Mauro Conti, Seungwon ShinNDSS 2022
- ConfMask: Enabling Privacy-Preserving Configuration Sharing via AnonymizationYuejie Wang, Qiutong Men, Yao Xiao, Yongting Chen et al.SIGCOMM 2024 · 1 citation
- You Can Obfuscate, but You Cannot Hide: CrossPoint Attacks against Network Topology ObfuscationXuanbo Huang, Kaiping Xue, Lutong Chen, Mingrui Ai et al.USENIX Security 2024 · 10 citations
- Towards Fine-grained Network Security Forensics and Diagnosis in the SDN EraHaopei Wang, Guangliang Yang, Phakpoom Chinprutthiwong, Lei Xu et al.CCS 2018 · 44 citations
- ProTO: Proactive Topology Obfuscation Against Adversarial Network Topology InferenceTao Hou, Zhe Qu, Tao Wang, Zhuo Lu et al.INFOCOM 2020 · 27 citations
