Secure Inter-domain Forwarding Loop Test in Software Defined Networks

Yuan Zhang,Boyu Zhu,Yixin Fang,Suxin Guo,Aidong Zhang,Sheng Zhong
DOI: https://doi.org/10.1109/TDSC.2017.2731773
2020-01-01
IEEE Transactions on Dependable and Secure Computing
Abstract:Debugging a traditional network is notoriously difficult due to network devices’ heterogeneity and protocols’ decentralized nature, but Software-Defined Networking (SDN) is changing this predicament. Recent works have provided very nice approaches for an administrator to perform several fundamental network tests in a single-domain SDN network. However, how to perform these tests securely in multi-domain networks still remains open. In this paper, we study the highly challenging problem of inter-domain forwarding loop test in a SDN environment. We present two novel testing protocols that can be used for inter-domain loop tests. Both protocols are secure in the sense that they protect each domain's private information about its topology and configuration. The first protocol, based on random sampling, is highly efficient with a small error probability diminishing exponentially in the sample size. The second protocol, based on secure set intersection test, guarantees 100 percent accuracy of the result, although not as efficient as the first one. We provide rigorous proofs for the security and accuracy guarantees, and show our protocols have very good efficiency by testing them with real-world network data.
What problem does this paper attempt to address?