NetHide: Secure and Practical Network Topology Obfuscation
Roland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever, Martin T. Vechev
摘要
Simple path tracing tools such as traceroute allow malicious users to infer network topologies remotely and use that knowledge to craft advanced denial-of-service (DoS) attacks such as Link-Flooding Attacks (LFAs). Yet, despite the risk, most network operators still allow path tracing as it is an essential network debugging tool. In this paper, we present NetHide, a network topology obfuscation framework that mitigates LFAs while preserving the practicality of path tracing tools. The key idea behind NetHide is to formulate network obfuscation as a multi-objective optimization problem that allows for a flexible tradeoff between security (encoded as hard constraints) and usability (encoded as soft constraints). While solving this problem exactly is hard, we show that NetHide can obfuscate topologies at scale by only considering a subset of the candidate solutions and without reducing obfuscation quality. In practice, NetHide obfuscates the topology by intercepting and modifying path tracing probes directly in the data plane. We show that this process can be done at line-rate, in a stateless fashion, by leveraging the latest generation of programmable network devices. We fully implemented NetHide and evaluated it on realistic topologies. Our results show that NetHide is able to obfuscate large topologies (> 150 nodes) while preserving near-perfect debugging capabilities. In particular, we show that operators can still precisely trace back > 90 % of link failures despite obfuscation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- ICARUS: Attacking low Earth orbit satellite networksGiacomo Giuliari, Tommaso Ciussani, Adrian Perrig, Ankit SinglaUSENIX ATC 2021 · 被引用 99 次
- On the Feasibility of Rerouting-Based DDoS DefensesMuoi Tran, Min Suk Kang, Hsu-Chun Hsiao, Wei-Hsuan Chiang 等S&P 2019 · 被引用 39 次
- DeeP4R: Deep Packet Inspection in P4 using Packet RecirculationSahil Gupta, Devashish Gosain, Minseok Kwon, Hrishikesh B. AcharyaINFOCOM 2023 · 被引用 24 次
- IMap: Fast and Scalable In-Network Scanning with Programmable SwitchesGuanyu Li, Menghao Zhang, Cheng Guo, Han Bao 等NSDI 2022 · 被引用 14 次
- Enhancing Network Attack Detection with Distributed and In-Network Data Collection SystemSeyed Mohammad Mehdi Mirnajafizadeh, Ashwin Raam Sethuram, David Mohaisen, DaeHun Nyang 等USENIX Security 2024 · 被引用 12 次
它引用的顶会 Paper3
- SPIFFY: Inducing Cost-Detectability Tradeoffs for Persistent Link-Flooding AttacksMin Suk Kang, Virgil D. Gligor, Vyas SekarNDSS 2016 · 被引用 123 次
- Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP RoutingJared M. Smith, Max SchuchardS&P 2018 · 被引用 71 次
- SIBRA: Scalable Internet Bandwidth Reservation ArchitectureCristina Basescu, Raphael M. Reischuk, Pawel Szalachowski, Adrian Perrig 等NDSS 2016 · 被引用 61 次
相关 Paper
- EqualNet: A Secure and Practical Defense for Long-term Network Topology ObfuscationJinwoo Kim, Eduard Marin, Mauro Conti, Seungwon ShinNDSS 2022
- ConfMask: Enabling Privacy-Preserving Configuration Sharing via AnonymizationYuejie Wang, Qiutong Men, Yao Xiao, Yongting Chen 等SIGCOMM 2024 · 被引用 1 次
- You Can Obfuscate, but You Cannot Hide: CrossPoint Attacks against Network Topology ObfuscationXuanbo Huang, Kaiping Xue, Lutong Chen, Mingrui Ai 等USENIX Security 2024 · 被引用 10 次
- Towards Fine-grained Network Security Forensics and Diagnosis in the SDN EraHaopei Wang, Guangliang Yang, Phakpoom Chinprutthiwong, Lei Xu 等CCS 2018 · 被引用 44 次
- ProTO: Proactive Topology Obfuscation Against Adversarial Network Topology InferenceTao Hou, Zhe Qu, Tao Wang, Zhuo Lu 等INFOCOM 2020 · 被引用 27 次
