When Match Fields Do Not Need to Match: Buffered Packets Hijacking in SDN
Jiahao Cao, Renjie Xie, Kun Sun, Qi Li, Guofei Gu, Mingwei Xu
摘要
Software-Defined Networking (SDN) greatly meets the need in industry for programmable, agile, and dynamic networks by deploying diversified SDN applications on a centralized controller. However, SDN application ecosystem inevitably introduces new security threats since compromised or malicious applications can significantly disrupt network operations. Thus, a number of effective security enhancement systems have been developed to defend against potential attacks from SDN applications. In this paper, we identify a new vulnerability on flow rule installation in SDN, namely, buffered packet hijacking, which can be exploited by malicious applications to launch effective attacks bypassing all existing defense systems. The root cause of this vulnerability lies in that SDN systems do not check the inconsistency between buffer IDs and match fields when an application attempts to install flow rules. Thus, a malicious application can manipulate buffer IDs to hijack buffered packets even though they do not match any installed flow rules. We design effective attacks exploiting this vulnerability to disrupt all three SDN layers, i.e., application layer, data plane layer, and control layer. First, by modifying buffered packets and resending them to controllers, a malicious application can poison other applications. Second, by manipulating forwarding behaviors of buffered packets, a malicious application can not only disrupt TCP connections of flows but also make flows bypass network security policies. Third, by copying massive buffered packets to controllers, a malicious application can saturate the bandwidth of SDN control channels and their computing resources. We demonstrate the feasibility and effectiveness of these attacks with both theoretical analysis and experiments in a real SDN testbed. Finally, we develop a lightweight defense system that can be readily deployed in existing SDN controllers as a patch.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Causal Analysis for Software-Defined Networking AttacksBenjamin E. Ujcich, Samuel Jero, Richard Skowyra, Adam Bates 等USENIX Security 2021 · 被引用 26 次
- Manipulating OpenFlow Link Discovery Packet Forwarding for Topology PoisoningMingming Chen, Thomas La Porta, Teryl Taylor, Frederico Araujo 等CCS 2024 · 被引用 8 次
- When Address Learning Goes Wrong: Inducing Forwarding Loops and DoS Amplification in SDNDezhang Kong, Yilun Zhang, Zekun Xie, Ningpeng Zheng 等USENIX Security 2026
它引用的顶会 Paper5
- DELTA: A Security Assessment Framework for Software-Defined NetworksSeungsoo Lee, Changhoon Yoon, Chanhee Lee, Seungwon Shin 等NDSS 2017 · 被引用 128 次
- The CrossPath Attack: Disrupting the SDN Control Channel via Shared LinksJiahao Cao, Qi Li, Renjie Xie, Kun Sun 等USENIX Security 2019 · 被引用 68 次
- Cross-App Poisoning in Software-Defined NetworkingBenjamin E. Ujcich, Samuel Jero, Anne Edmundson, Qi Wang 等CCS 2018 · 被引用 62 次
- Identifier Binding Attacks and Defenses in Software-Defined NetworksSamuel Jero, William Koch, Richard Skowyra, Hamed Okhravi 等USENIX Security 2017 · 被引用 55 次
- Towards Fine-grained Network Security Forensics and Diagnosis in the SDN EraHaopei Wang, Guangliang Yang, Phakpoom Chinprutthiwong, Lei Xu 等CCS 2018 · 被引用 44 次
相关 Paper
- SDN Application Backdoor: Disrupting the Service via Poisoning the TopologyShuhua Deng, Xian Qing, Xiaofan Li, Xing Gao 等INFOCOM 2023 · 被引用 8 次
- Attacking the Brain: Races in the SDN Control PlaneLei Xu, Jeff Huang, Sungmin Hong, Jialong Zhang 等USENIX Security 2017 · 被引用 77 次
- Flow Table Security in SDN: Adversarial Reconnaissance and Intelligent AttacksMingli Yu, Ting He, Patrick Drew McDaniel, Quinn K. BurkeINFOCOM 2020 · 被引用 24 次
- An In-depth Look Into SDN Topology Discovery Mechanisms: Novel Attacks and Practical CountermeasuresEduard Marin, Nicola Bucciol, Mauro ContiCCS 2019 · 被引用 60 次
- Automated Discovery of Cross-Plane Event-Based Vulnerabilities in Software-Defined NetworkingBenjamin E. Ujcich, Samuel Jero, Richard Skowyra, Steven R. Gomez 等NDSS 2020
