Deakin University
Browse

DDoS attacks on data plane of software-defined network: are they possible?

Download all (2.7 MB)
Version 2 2024-06-05, 05:27
Version 1 2016-12-01, 00:00
journal contribution
posted on 2024-06-05, 05:27 authored by X Wu, M Liu, W Dou, S Yu
With software-defined networking (SDN) becoming the leading technology for large-scale networks, it is definitely expected that SDN will suffer various types of distributed denial-of-service (DDoS) attacks because of its centralized control logic. However, almost all of existing works concentrate on the controller overloading DDoS attacks, while vulnerabilities exposed by data plane of SDN for DDoS attacks are largely ignored. In this paper, we firstly investigate a flow rule flooding DDoS attack. By thoroughly analyzing the flow table size and miss rate, we find that attackers are able to inflict significant performance degradation over the system with limited volume of attack resource. We then prove that it is possible for attackers to maximize the performance degradation and minimize the attack rate at the same time. Besides the flooding DDoS attack, we also study a novel DDoS attack targeting data plane of SDN. By utilizing the entry lifetime management mechanism of flow tables, this attack almost never exhibits an intensive controller access behavior. It flies under the radar by inflicting non-notable performance impact on the system, while it creates heavy long-term financial burden on the target application. Finally, we present a potential countermeasure for this stealthy DDoS attack. Through extensive experiments, we conclude that DDoS attacks targeting data plane are possible.

History

Related Materials

  1. 1.

Location

Chichester, Eng.

Open access

  • Yes

Language

eng

Publication classification

C Journal article, C1 Refereed article in a scholarly journal

Copyright notice

2016, John Wiley & Sons

Journal

Security and communication networks

Volume

9

Pagination

5444-5459

ISSN

1939-0114

eISSN

1939-0122

Issue

18

Publisher

John Wiley & Sons