Towards Fine-grained Network Security Forensics and Diagnosis in the SDN Era
Haopei Wang, Guangliang Yang, Phakpoom Chinprutthiwong, Lei Xu, Yangyong Zhang, Guofei Gu
Abstract
Diagnosing network security issues in traditional networks is difficult. It is even more frustrating in the emerging Software Defined Networks. The data/control plane decoupling of the SDN framework makes the traditional network troubleshooting tools unsuitable for pinpointing the root cause in the control plane. In this paper, we propose ForenGuard, which provides flow-level forensics and diagnosis functions in SDN networks. Unlike traditional forensics tools that only involve either network level or host level, Foren-Guard monitors and records the runtime activities and their causal dependencies involving both the SDN control plane and data plane. Starting with a forwarding problem (e.g., disconnection) which could be caused by a security issue, ForenGuard can backtrack the previous activities in both the control and data plane through causal relationships and pinpoint the root cause of the problem. ForenGuard also provides a user-friendly interface that allows users to specify the detection point and diagnose complicated network problems. We implement a prototype system of ForenGuard on top of the Floodlight controller and use it to diagnose several real control plane attacks. We show that ForenGuard can quickly display causal relationships of activities and help to narrow down the range of suspicious activities that could be the root causes. Our performance evaluation shows that ForenGuard will add minor runtime overhead to the SDN control plane and can scale well in various network workloads.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 552e9849-e860-4068-a618-b7158e6cb862Cited by top-tier papers9
- An In-depth Look Into SDN Topology Discovery Mechanisms: Novel Attacks and Practical CountermeasuresEduard Marin, Nicola Bucciol, Mauro ContiCCS 2019 · 60 citations
- Unexpected Data Dependency Creation and Chaining: A New Attack to SDNFeng Xiao, Jinquan Zhang, Jianwei Huang, Guofei Gu et al.S&P 2020 · 31 citations
- Causal Analysis for Software-Defined Networking AttacksBenjamin E. Ujcich, Samuel Jero, Richard Skowyra, Adam Bates et al.USENIX Security 2021 · 26 citations
- Hawkeye: Diagnosing RDMA Network Performance Anomalies with PFC ProvenanceShicheng Wang, Menghao Zhang, Xiao Li, Qiyang Peng et al.SIGCOMM 2025 · 7 citations
- ProvGuard: Detecting SDN Control Policy Manipulation via Contextual Semantics of Provenance GraphsZiwen Liu, Jian Mao, Jun Zeng, Jiawei Li et al.NDSS 2025
Builds on5
- DELTA: A Security Assessment Framework for Software-Defined NetworksSeungsoo Lee, Changhoon Yoon, Chanhee Lee, Seungwon Shin et al.NDSS 2017 · 128 citations
- RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow TrackingYang Ji, Sangho Lee, Evan Downing, Weiren Wang et al.CCS 2017 · 119 citations
- Attacking the Brain: Races in the SDN Control PlaneLei Xu, Jeff Huang, Sungmin Hong, Jialong Zhang et al.USENIX Security 2017 · 77 citations
- Identifier Binding Attacks and Defenses in Software-Defined NetworksSamuel Jero, William Koch, Richard Skowyra, Hamed Okhravi et al.USENIX Security 2017 · 55 citations
- Towards SDN-Defined Programmable BYOD (Bring Your Own Device) SecuritySungmin Hong, Robert Baykov, Lei Xu, Srinath Nadimpalli et al.NDSS 2016 · 52 citations
Related papers
- SDN Application Backdoor: Disrupting the Service via Poisoning the TopologyShuhua Deng, Xian Qing, Xiaofan Li, Xing Gao et al.INFOCOM 2023 · 8 citations
- Diagnosing Programmable Data Plane Attacks with Provenance ObservabilityDhiraj Saharia, Ashish Gehani, Vinod Yegneswaran, Benjamin E. UjcichCCS 2026
- AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksSeungsoo Lee, Seungwon Woo, Jinwoo Kim, Vinod Yegneswaran et al.INFOCOM 2020 · 13 citations
- Automated Discovery of Cross-Plane Event-Based Vulnerabilities in Software-Defined NetworkingBenjamin E. Ujcich, Samuel Jero, Richard Skowyra, Steven R. Gomez et al.NDSS 2020
- Cross-App Poisoning in Software-Defined NetworkingBenjamin E. Ujcich, Samuel Jero, Anne Edmundson, Qi Wang et al.CCS 2018 · 62 citations
