When Match Fields Do Not Need to Match: Buffered Packets Hijacking in SDN
Jiahao Cao, Renjie Xie, Kun Sun, Qi Li, Guofei Gu, Mingwei Xu
Abstract
Software-Defined Networking (SDN) greatly meets the need in industry for programmable, agile, and dynamic networks by deploying diversified SDN applications on a centralized controller. However, SDN application ecosystem inevitably introduces new security threats since compromised or malicious applications can significantly disrupt network operations. Thus, a number of effective security enhancement systems have been developed to defend against potential attacks from SDN applications. In this paper, we identify a new vulnerability on flow rule installation in SDN, namely, buffered packet hijacking, which can be exploited by malicious applications to launch effective attacks bypassing all existing defense systems. The root cause of this vulnerability lies in that SDN systems do not check the inconsistency between buffer IDs and match fields when an application attempts to install flow rules. Thus, a malicious application can manipulate buffer IDs to hijack buffered packets even though they do not match any installed flow rules. We design effective attacks exploiting this vulnerability to disrupt all three SDN layers, i.e., application layer, data plane layer, and control layer. First, by modifying buffered packets and resending them to controllers, a malicious application can poison other applications. Second, by manipulating forwarding behaviors of buffered packets, a malicious application can not only disrupt TCP connections of flows but also make flows bypass network security policies. Third, by copying massive buffered packets to controllers, a malicious application can saturate the bandwidth of SDN control channels and their computing resources. We demonstrate the feasibility and effectiveness of these attacks with both theoretical analysis and experiments in a real SDN testbed. Finally, we develop a lightweight defense system that can be readily deployed in existing SDN controllers as a patch.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 400081f3-9012-4bd0-852e-feb4d15e12abCited by top-tier papers3
- Causal Analysis for Software-Defined Networking AttacksBenjamin E. Ujcich, Samuel Jero, Richard Skowyra, Adam Bates et al.USENIX Security 2021 · 26 citations
- Manipulating OpenFlow Link Discovery Packet Forwarding for Topology PoisoningMingming Chen, Thomas La Porta, Teryl Taylor, Frederico Araujo et al.CCS 2024 · 8 citations
- When Address Learning Goes Wrong: Inducing Forwarding Loops and DoS Amplification in SDNDezhang Kong, Yilun Zhang, Zekun Xie, Ningpeng Zheng et al.USENIX Security 2026
Builds on5
- DELTA: A Security Assessment Framework for Software-Defined NetworksSeungsoo Lee, Changhoon Yoon, Chanhee Lee, Seungwon Shin et al.NDSS 2017 · 128 citations
- The CrossPath Attack: Disrupting the SDN Control Channel via Shared LinksJiahao Cao, Qi Li, Renjie Xie, Kun Sun et al.USENIX Security 2019 · 68 citations
- Cross-App Poisoning in Software-Defined NetworkingBenjamin E. Ujcich, Samuel Jero, Anne Edmundson, Qi Wang et al.CCS 2018 · 62 citations
- Identifier Binding Attacks and Defenses in Software-Defined NetworksSamuel Jero, William Koch, Richard Skowyra, Hamed Okhravi et al.USENIX Security 2017 · 55 citations
- Towards Fine-grained Network Security Forensics and Diagnosis in the SDN EraHaopei Wang, Guangliang Yang, Phakpoom Chinprutthiwong, Lei Xu et al.CCS 2018 · 44 citations
Related papers
- SDN Application Backdoor: Disrupting the Service via Poisoning the TopologyShuhua Deng, Xian Qing, Xiaofan Li, Xing Gao et al.INFOCOM 2023 · 8 citations
- Attacking the Brain: Races in the SDN Control PlaneLei Xu, Jeff Huang, Sungmin Hong, Jialong Zhang et al.USENIX Security 2017 · 77 citations
- Flow Table Security in SDN: Adversarial Reconnaissance and Intelligent AttacksMingli Yu, Ting He, Patrick Drew McDaniel, Quinn K. BurkeINFOCOM 2020 · 24 citations
- An In-depth Look Into SDN Topology Discovery Mechanisms: Novel Attacks and Practical CountermeasuresEduard Marin, Nicola Bucciol, Mauro ContiCCS 2019 · 60 citations
- Automated Discovery of Cross-Plane Event-Based Vulnerabilities in Software-Defined NetworkingBenjamin E. Ujcich, Samuel Jero, Richard Skowyra, Steven R. Gomez et al.NDSS 2020
