Mitigation Of Security Attacks In The Sdn Data Plane Using P4-Enabled Switches

13TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATION SYSTEMS (IEEE ANTS)(2019)

引用 7|浏览8
暂无评分
摘要
This paper presents a study and demonstration of some of the commonly seen internal security attacks and related countermeasures using P4, a dataplane programming language. The idea is that the vulnerabilities arising in programmable data planes are sufficiently mitigated with this P4 implementation. This also provides users with the flexibility to add or drop security features in the deployed switches, better visibility into the defense system owing to its open source nature and the portability of these P4 programs across many different vendors and devices. We evaluate our P4 code on software and hardware switches to detect IP-address spoofing attacks. The results show that attack packets are always detected and dropped, while the throughput remains unaffected and nearly constant across varying fractions of malicious packets injected in the network.
更多
查看译文
关键词
SDN data plane,P4-enabled switches,dataplane programming language,programmable data planes,security features,deployed switches,defense system,open source nature,hardware switches,IP-address spoofing attacks,internal security attacks,security attack mitigation,P4 code,software switches,malicious packets
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要