Javascript must be enabled to continue!
TopoSleuth: A Context-Aware, Multi-Layered Defense Framework Using Decoy Links and Behavioral Profiling Against SDN Topology Discovery Attacks
View through CrossRef
Abstract
Software Defined Networking (SDN) is a diversified networking paradigm that is centralized, dynamic, and enables traffic control and administration through flexible network programmability. The controller and its applications have a holistic view of the underlying physical topology, including switches, ports, hosts, and links. With the increasing significance and popularity of SDN, novel attacks have arisen that can distort the controller’s view of topology. A corrupt topology view can have a catastrophic effect on the controller and topologically dependent services, resulting in falsified routing and forwarding decisions. In this paper, we have proposed a multi-layered, context-aware defense framework called TopoSleuth, that complements the current controller services, Link Discovery Service (LDS) and Host Tracking Service (HTS), with four lightweight modules: (i) Topology Monitor (TM) for correlation and escalation logic; (ii) Decoy Engine (DE) for deception-based tripwires called decoy links; (iii) Behavioral Profiler (BP) for temporal/structural anomalies; and (iv) Multi-hop Validator (MV) for on-demand active probing. The current controllers are seamlessly integrated with TopoSleuth. Because of its defense-in-depth methodology, our solution is effective against topology poisoning attacks, including combination attacks and even topology freezing attacks, for which there is currently no known countermeasure.
Springer Science and Business Media LLC
Title: TopoSleuth: A Context-Aware, Multi-Layered Defense Framework Using Decoy Links and Behavioral Profiling Against SDN Topology Discovery Attacks
Description:
Abstract
Software Defined Networking (SDN) is a diversified networking paradigm that is centralized, dynamic, and enables traffic control and administration through flexible network programmability.
The controller and its applications have a holistic view of the underlying physical topology, including switches, ports, hosts, and links.
With the increasing significance and popularity of SDN, novel attacks have arisen that can distort the controller’s view of topology.
A corrupt topology view can have a catastrophic effect on the controller and topologically dependent services, resulting in falsified routing and forwarding decisions.
In this paper, we have proposed a multi-layered, context-aware defense framework called TopoSleuth, that complements the current controller services, Link Discovery Service (LDS) and Host Tracking Service (HTS), with four lightweight modules: (i) Topology Monitor (TM) for correlation and escalation logic; (ii) Decoy Engine (DE) for deception-based tripwires called decoy links; (iii) Behavioral Profiler (BP) for temporal/structural anomalies; and (iv) Multi-hop Validator (MV) for on-demand active probing.
The current controllers are seamlessly integrated with TopoSleuth.
Because of its defense-in-depth methodology, our solution is effective against topology poisoning attacks, including combination attacks and even topology freezing attacks, for which there is currently no known countermeasure.
Related Results
Comparative Analysis Of A Multi-Layered Weapon System For City Air Defense In The Modern Warfare
Comparative Analysis Of A Multi-Layered Weapon System For City Air Defense In The Modern Warfare
In the era of modern warfare, urban defense is a very important aspect to maintain the security and stability of a country. Because modern war is a non-military war in which develo...
Deception-Based Security Framework for IoT: An Empirical Study
Deception-Based Security Framework for IoT: An Empirical Study
<p><b>A large number of Internet of Things (IoT) devices in use has provided a vast attack surface. The security in IoT devices is a significant challenge considering c...
How to train a post-processor for tandem mass spectrometry proteomics database search while maintaining control of the false discovery rate
How to train a post-processor for tandem mass spectrometry proteomics database search while maintaining control of the false discovery rate
Abstract
Decoy-based methods are a popular choice for the statistical validation of peptide detections in tandem mass spectrometry proteomics data. Such methods can...
Toward secure AI: detection and mitigation of backdoor attacks
Toward secure AI: detection and mitigation of backdoor attacks
Purpose
This survey aims to provide a comprehensive and structured understanding of backdoor attacks across different domains. It seeks to establish a unified t...
Keterlibatan Guru PAI dalam Menangani Perilaku Bullying Siswa di SDN Lembang
Keterlibatan Guru PAI dalam Menangani Perilaku Bullying Siswa di SDN Lembang
Abstract. This study is motivated by the problem of student bullying behavior that occurs in SDN Lembang, PAI teachers have involvement in dealing with and preventing bullying beha...
The development of the asymmetrically dominated decoy effect in young children
The development of the asymmetrically dominated decoy effect in young children
AbstractOne classic example of context-independent violations is the asymmetrically dominated decoy effect, in which adding a decoy option (inferior option) to a set of original op...
Behavioral Economics: The Decoy Effect
Behavioral Economics: The Decoy Effect
Behavioral economics blends psychology and economics to determine how psychological triggers or nudges influence people's decision-making. The decoy effect has been a particular fo...
Defining Profiling
Defining Profiling
Profiling is a highly evocative term with multiple meanings, used in both specialist and non-specialist contexts. Drawing attention to the innovative feature of profiling as a form...

