Achieving Efficient Multipath Validation in Software-Defined Networks
Bing Hu, Yuanguo Bi, Kui Wu, Zixuan Huang, Rongfei Zeng
摘要
The programmability of Software-Defined Networks (SDN) enables multipath routing through dynamic adjustments and optimizations of network resources. However, a compromised switch can violate packet forwarding rules, creating serious security vulnerability. While path validation ensures packets follow designated paths, mainstream methods impose excessive computational burden on the controller and significant storage overhead on switches due to the uncertainty and potentially large number of packet forwarding paths. To address these issues, we propose a Naive Packet-level MultiPath Validation Scheme (NPM-PVS) as the first attempt to verify multiple forwarding paths in SDN. Building on NPM-PVS, we introduce an Enhanced Packet-level MultiPath Validation Scheme (EPM-PVS), which uses a Supplementary Validation Information (SVI) generation method to reduce the controller's load by ensuring consistent validation for packets of a network flow across various forwarding paths. To further improve the efficiency of EPM-PVS, we propose a Flow-level MultiPath Validation Scheme (FM-PVS) and implement a validation information compression method to minimize data plane storage overhead. Additionally, we introduce an anomaly switch identification method to locate compromised switches when path validation fails at the controller. Evaluation results demonstrate that the proposed FM-PVS achieves low switch storage overhead and reduces the computational burden on the controller.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- A Lightweight Path Validation Scheme in Software-Defined NetworksBing Hu, Yuanguo Bi, Kui Wu, Rao Fu 等INFOCOM 2024 · 被引用 4 次
- 1BIT: Persistent Path Validation with Customized Noise Signal CharacteristicsKeji Miao, Jie Yuan, Xinghai Wei, Xingwu Wang 等CCS 2025
- ProvGuard: Detecting SDN Control Policy Manipulation via Contextual Semantics of Provenance GraphsZiwen Liu, Jian Mao, Jun Zeng, Jiawei Li 等NDSS 2025
- The CrossPath Attack: Disrupting the SDN Control Channel via Shared LinksJiahao Cao, Qi Li, Renjie Xie, Kun Sun 等USENIX Security 2019 · 被引用 68 次
- P4Inv: Inferring Packet Invariants for Verification of Stateful P4 ProgramsDelong Zhang, Chong Ye, Fei HeINFOCOM 2024 · 被引用 3 次
