vix.ing · top · new · best · stats · spec

Fingerprinting OpenFlow controllers: The first step to attack an SDN\n control plane

2016/11/07 by Abdelhadi Azzouni, Azzouni, Abdelhadi, Othmen Braham +8 · 1 voice
Computer Science · #Internet Traffic Analysis and Secure E-voting #Software-Defined Networks and 5G #Network Security and Intrusion Detection

paper · pdf · doi:10.48550/arxiv.1611.02370

Abstract

Software-Defined Networking (SDN) controllers are considered as Network\nOperating Systems (NOSs) and often viewed as a single point of failure.\nDetecting which SDN controller is managing a target network is a big step for\nan attacker to launch specific/effective attacks against it. In this paper, we\ndemonstrate the feasibility of fingerpirinting SDN controllers. We propose\ntechniques allowing an attacker placed in the data plane, which is supposed to\nbe physically separate from the control plane, to detect which controller is\nmanaging the network. To the best of our knowledge, this is the first work on\nfingerprinting SDN controllers, with as primary goal to emphasize the necessity\nto highly secure the controller. We focus on OpenFlow-based SDN networks since\nOpenFlow is currently the most deployed SDN technology by hardware and software\nvendors.\n

Discussions

Related