Behavior Anomaly Detection in SDN Control Plane: A Case Study of Topology Discovery Attacks

Joint Authors

Chou, Li-Der
Liu, Chien-Chang
Lai, Meng-Sheng
Chiu, Kai-Cheng
Tu, Hsuan-Hao
Su, Sen
Lai, Chun-Lin
Yen, Chia-Kuan
Tsai, Wei-Hsiang

Source

Wireless Communications and Mobile Computing

Issue

Vol. 2020, Issue 2020 (31 Dec. 2020), pp.1-16, 16 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2020-11-21

Country of Publication

Egypt

No. of Pages

16

Main Subjects

Information Technology and Computer Science

Abstract EN

Software-defined networking controllers use the OpenFlow discovery protocol (OFDP) to collect network topology status.

The OFDP detects the link between switches by generating link layer discovery protocol (LLDP) packets.

However, OFDP is not a security protocol.

Attackers can use it to perform topology discovery via injection, man-in-the-middle, and flooding attacks to confuse the network topology.

This study proposes a correlation-based topology anomaly detection mechanism.

Spearman’s rank correlation is used to analyze the network traffic between links and measure the round-trip time of each LLDP frame to determine whether a topology discovery via man-in-the-middle attack exists.

This study also adds a dynamic authentication key and counting mechanism in the LLDP frame to prevent attackers from using topology discovery via injection attack to generate fake links and topology discovery via flooding attack to cause network routing or switching abnormalities.

American Psychological Association (APA)

Chou, Li-Der& Liu, Chien-Chang& Lai, Meng-Sheng& Chiu, Kai-Cheng& Tu, Hsuan-Hao& Su, Sen…[et al.]. 2020. Behavior Anomaly Detection in SDN Control Plane: A Case Study of Topology Discovery Attacks. Wireless Communications and Mobile Computing،Vol. 2020, no. 2020, pp.1-16.
https://search.emarefa.net/detail/BIM-1214948

Modern Language Association (MLA)

Chou, Li-Der…[et al.]. Behavior Anomaly Detection in SDN Control Plane: A Case Study of Topology Discovery Attacks. Wireless Communications and Mobile Computing No. 2020 (2020), pp.1-16.
https://search.emarefa.net/detail/BIM-1214948

American Medical Association (AMA)

Chou, Li-Der& Liu, Chien-Chang& Lai, Meng-Sheng& Chiu, Kai-Cheng& Tu, Hsuan-Hao& Su, Sen…[et al.]. Behavior Anomaly Detection in SDN Control Plane: A Case Study of Topology Discovery Attacks. Wireless Communications and Mobile Computing. 2020. Vol. 2020, no. 2020, pp.1-16.
https://search.emarefa.net/detail/BIM-1214948

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1214948