EqualNet: A Secure and Practical Defense for Long-term Network Topology Obfuscation
Jinwoo Kim, Eduard Marin, Mauro Conti, Seungwon Shin
摘要
Path tracing tools, such as traceroute, are simple yet fundamental network debugging tools for network operators to detect and fix network failures. Unfortunately, adversaries can also use such tools to retrieve previously unknown network topology information which is key to realizing sophisticated Denialof-Service attacks, such as Link Flooding Attacks (LFAs), more efficiently. Over the last few years, several network obfuscation defenses have been proposed to proactively mitigate LFAs by exposing virtual (fake) topologies that conceal potential bottleneck network links from adversaries. However, to date there has been no comprehensive and systematic analysis of the level of security and utility their virtual topologies offer. A critical analysis is thus a necessary step towards better understanding their limitations and building stronger and more practical defenses against LFAs. In this paper, we first conduct a security analysis of the three state-of-the-art network obfuscation defenses. Our analysis reveals four important, common limitations that can significantly decrease the security and utility of their virtual topologies. Motivated by our findings, we present EqualNet, a secure and practical proactive defense for long-term network topology obfuscation that alleviates LFAs within a network domain. EqualNet aims to equalize tracing flow distributions over nodes and links so that adversaries are unable to distinguish which of them are the most important ones, thus significantly increasing the cost of performing LFAs. Meanwhile, EqualNet preserves subnet information, helping network operators who use path tracing tools to debug their networks. To demonstrate its feasibility, we implement a full prototype of it using Software-Defined Networking (SDN) and perform extensive evaluations both in software and hardware. Our results show that EqualNet is effective at equalizing the tracing flow distributions of small, medium and large networks even when only a small number of routers within the network support SDN. Finally, we analyze the security of EqualNet against a wide variety of attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- You Can Obfuscate, but You Cannot Hide: CrossPoint Attacks against Network Topology ObfuscationXuanbo Huang, Kaiping Xue, Lutong Chen, Mingrui Ai 等USENIX Security 2024 · 被引用 10 次
- ConfMask: Enabling Privacy-Preserving Configuration Sharing via AnonymizationYuejie Wang, Qiutong Men, Yao Xiao, Yongting Chen 等SIGCOMM 2024 · 被引用 1 次
- CoPHo: Classifier-guided Conditional Topology Generation with Persistent HomologyGongli Xi, Ye Tian, Mengyu Yang, Zhenyu Zhao 等KDD 2026
它引用的顶会 Paper4
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- SPIFFY: Inducing Cost-Detectability Tradeoffs for Persistent Link-Flooding AttacksMin Suk Kang, Virgil D. Gligor, Vyas SekarNDSS 2016 · 被引用 123 次
- NetHide: Secure and Practical Network Topology ObfuscationRoland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever 等USENIX Security 2018 · 被引用 84 次
- The CrossPath Attack: Disrupting the SDN Control Channel via Shared LinksJiahao Cao, Qi Li, Renjie Xie, Kun Sun 等USENIX Security 2019 · 被引用 68 次
相关 Paper
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 被引用 100 次
- Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable SwitchesHuancheng Zhou, Sungmin Hong, Yangyang Liu, Xiapu Luo 等S&P 2023
- An In-depth Look Into SDN Topology Discovery Mechanisms: Novel Attacks and Practical CountermeasuresEduard Marin, Nicola Bucciol, Mauro ContiCCS 2019 · 被引用 60 次
- Towards Fine-grained Network Security Forensics and Diagnosis in the SDN EraHaopei Wang, Guangliang Yang, Phakpoom Chinprutthiwong, Lei Xu 等CCS 2018 · 被引用 44 次
- ProTO: Proactive Topology Obfuscation Against Adversarial Network Topology InferenceTao Hou, Zhe Qu, Tao Wang, Zhuo Lu 等INFOCOM 2020 · 被引用 27 次
