IA-DD: An SDN Topological Poisoning Attack Defense Scheme Based on Blockchain

Bin Gu,Xingwei Wang,Kaiqi Yang,Yu Wang,Qiang He
DOI: https://doi.org/10.1109/MSN57253.2022.00132
2022-01-01
Abstract:Software defined networking (SDN) have the advantages of centralized control, global visibility, and programmability, but these features also bring new security issues, such as Topological Poisoning Attack (TPA), where attackers can attack topology discovery services by stealing host locations or forging link information. Considering the three levels of identity, data package and path, this paper designs a chain authentication defense scheme. The scheme includes authentication mechanism, transaction information storage mechanism, source IP authentication mechanism and smart contract notification mechanism. The received packets are authenticated by digital signature algorithm, and the trusted identity and location information are stored securely. At the same time, an improved block storage structure is designed to avoid data redundancy, and malicious information is processed by smart contract notification and stream rule installation. The experimental results show that the defense scheme designed in this paper can effectively defend against TPA attacks. Compared with the benchmark mechanism, the deployment of this scheme has less impact on controller performance and less impact on the delay of topology discovery in SDN.
What problem does this paper attempt to address?