@inproceedings{f0067cd3f70a4622b7dc90963a7ff670,
title = "Detecting link fabrication attacks in software-defined networks",
abstract = "The Link Fabrication Attack (LFA) in Software-Defined Networking (SDN) involves an attacker forging a new link in the network, providing them with control over traffic which traverses the new malicious link. One method to perform this attack is through the relaying of topology discovery traffic, for which no comprehensive defense exists. This paper proposes to detect this attack using statistical analysis of link latencies. A novel solution has been designed requiring a new link to undergo a vetting period during which its latency is evaluated. This is subsequently compared against a baseline model for benign links. This solution is assessed against several implementations of the relay-type LFA. The trade-off between the length of the vetting period and the accuracy of the attack detection is analyzed. The results show how user-space relaying causes a sizable increase in latency which can be detected with a low number of samples, while relaying using kernel-space forwarding requires larger samples sets in order to be discovered.",
keywords = "Link fabrication, SDN, SDN security",
author = "Dylan Smyth and Sean McSweeney and Donna O'Shea and Victor Cionca",
note = "Publisher Copyright: {\textcopyright} 2017 IEEE.; 26th International Conference on Computer Communications and Networks, ICCCN 2017 ; Conference date: 31-07-2017 Through 03-08-2017",
year = "2017",
month = sep,
day = "14",
doi = "10.1109/ICCCN.2017.8038435",
language = "English",
series = "2017 26th International Conference on Computer Communications and Networks, ICCCN 2017",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
booktitle = "2017 26th International Conference on Computer Communications and Networks, ICCCN 2017",
}