TY - GEN
T1 - Exploiting pitfalls in software-defined networking implementation
AU - Smyth, Dylan
AU - Cionca, Victor
AU - McSweeney, Sean
AU - O'Shea, Donna
N1 - Publisher Copyright:
© 2016 IEEE.
PY - 2016/6/30
Y1 - 2016/6/30
N2 - The centralised control provided by Software-Defined Networking allows an increase in network security as all traffic can be vetted before leaving the attachment switch. Nevertheless, as in any complex system, there are implementation and policy compromises which lead to security vulnerabilities. This paper exploits such vulnerabilities to implement a suite of attacks, consisting of Address Resolution Protocol (ARP) cache poisoning, Man in the Middle, a firewall and access control bypassing port scan called a Phantom Host Scan, and a Distributed Denial of Service attack called a Phantom Storm which induces the participation of legitimate hosts. These attacks were successfully implemented in a Floodlight controlled network.
AB - The centralised control provided by Software-Defined Networking allows an increase in network security as all traffic can be vetted before leaving the attachment switch. Nevertheless, as in any complex system, there are implementation and policy compromises which lead to security vulnerabilities. This paper exploits such vulnerabilities to implement a suite of attacks, consisting of Address Resolution Protocol (ARP) cache poisoning, Man in the Middle, a firewall and access control bypassing port scan called a Phantom Host Scan, and a Distributed Denial of Service attack called a Phantom Storm which induces the participation of legitimate hosts. These attacks were successfully implemented in a Floodlight controlled network.
UR - https://www.scopus.com/pages/publications/84981344747
U2 - 10.1109/CyberSecPODS.2016.7502354
DO - 10.1109/CyberSecPODS.2016.7502354
M3 - Conference contribution
AN - SCOPUS:84981344747
T3 - 2016 International Conference on Cyber Security and Protection of Digital Services, Cyber Security 2016
BT - 2016 International Conference on Cyber Security and Protection of Digital Services, Cyber Security 2016
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2016 International Conference on Cyber Security and Protection of Digital Services, Cyber Security 2016
Y2 - 13 June 2016 through 14 June 2016
ER -