학술논문

Fingerprinting OpenFlow Controllers: The First Step to Attack an SDN Control Plane
Document Type
Conference
Source
2016 IEEE Global Communications Conference (GLOBECOM) Global Communications Conference (GLOBECOM), 2016 IEEE. :1-6 Dec, 2016
Subject
Communication, Networking and Broadcast Technologies
Components, Circuits, Devices and Systems
Signal Processing and Analysis
Switches
Time measurement
Time factors
Process control
Security
Testing
Language
Abstract
Software-Defined Networking (SDN) controllers are considered as Network Operating Systems (NOSs) and often viewed as a single point of failure. Detecting which SDN controller is managing a target network is a big step for an attacker to launch specific/effective attacks against it. In this paper, we demonstrate the feasibility of fingerpirinting SDN controllers. We propose techniques allowing an attacker placed in the data plane, which is supposed to be physically separate from the control plane, to detect which controller is managing the network. To the best of our knowledge, this is the first work on fingerprinting SDN controllers, with as primary goal to emphasize the necessity to highly secure the controller. We focus on OpenFlow-based SDN networks since OpenFlow is currently the most deployed SDN technology by hardware and software vendors.