{"title":"OpenFlow流表溢出攻击及对策","authors":"Ying Qian, Wanqing You, K. Qian","doi":"10.1109/EuCNC.2016.7561033","DOIUrl":null,"url":null,"abstract":"Software-defined Network (SDN) is proposed as a new concept in computer networks, which separates the control plane from data plane. And it provides a programmable network architecture that could facilitate network innovation rapidly. OpenFlow is a network protocol that standardizes the communications between OpenFlow controllers and OpenFlow switches. It is considered as an enabler of SDN. The flow table in OpenFlow switches plays a critical role in OpenFlow-based SDN, which stores the rules populated by the controllers for controlling and directing the packet flows in SDN. Nevertheless, they also become a new target of malicious attacks. This paper analyzes the flow table overflow attack, a type of denial of service attacks, and proposes a systematic way to mitigate the overflow in flow table.","PeriodicalId":416277,"journal":{"name":"2016 European Conference on Networks and Communications (EuCNC)","volume":"34 6 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-06-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"31","resultStr":"{\"title\":\"OpenFlow flow table overflow attacks and countermeasures\",\"authors\":\"Ying Qian, Wanqing You, K. Qian\",\"doi\":\"10.1109/EuCNC.2016.7561033\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Software-defined Network (SDN) is proposed as a new concept in computer networks, which separates the control plane from data plane. And it provides a programmable network architecture that could facilitate network innovation rapidly. OpenFlow is a network protocol that standardizes the communications between OpenFlow controllers and OpenFlow switches. It is considered as an enabler of SDN. The flow table in OpenFlow switches plays a critical role in OpenFlow-based SDN, which stores the rules populated by the controllers for controlling and directing the packet flows in SDN. Nevertheless, they also become a new target of malicious attacks. This paper analyzes the flow table overflow attack, a type of denial of service attacks, and proposes a systematic way to mitigate the overflow in flow table.\",\"PeriodicalId\":416277,\"journal\":{\"name\":\"2016 European Conference on Networks and Communications (EuCNC)\",\"volume\":\"34 6 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-06-27\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"31\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 European Conference on Networks and Communications (EuCNC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EuCNC.2016.7561033\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 European Conference on Networks and Communications (EuCNC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EuCNC.2016.7561033","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
OpenFlow flow table overflow attacks and countermeasures
Software-defined Network (SDN) is proposed as a new concept in computer networks, which separates the control plane from data plane. And it provides a programmable network architecture that could facilitate network innovation rapidly. OpenFlow is a network protocol that standardizes the communications between OpenFlow controllers and OpenFlow switches. It is considered as an enabler of SDN. The flow table in OpenFlow switches plays a critical role in OpenFlow-based SDN, which stores the rules populated by the controllers for controlling and directing the packet flows in SDN. Nevertheless, they also become a new target of malicious attacks. This paper analyzes the flow table overflow attack, a type of denial of service attacks, and proposes a systematic way to mitigate the overflow in flow table.