Causal Analysis for Software-Defined Networking Attacks

PROCEEDINGS OF THE 30TH USENIX SECURITY SYMPOSIUM(2021)

引用 8|浏览49
暂无评分
摘要
Software-defined networking (SDN) has emerged as a flexible network architecture for central and programmatic control. Although SDN can improve network security oversight and policy enforcement, ensuring the security of SDN from sophisticated attacks is an ongoing challenge for practitioners. Existing network forensics tools attempt to identify and track such attacks, but holistic causal reasoning across control and data planes remains challenging. We present PICOSDN, a provenance-informed causal observer for SDN attack analysis. PICOSDN leverages finegrained data and execution partitioning techniques, as well as a unified control and data plane model, to allow practitioners to efficiently determine root causes of attacks and to make informed decisions on mitigating them. We implement PICOSDN on the popular ONOS SDN controller. Our evaluation across several attack case studies shows that PICOSDN is practical for the identification, analysis, and mitigation of SDN attacks.
更多
查看译文
关键词
networking attacks,causal analysis,software-defined
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要