Skip to main navigation Skip to search Skip to main content

AIM-SDN: Aacking information mismanagement in SDN-datastores

  • Vaibhav Hemant Dixit
  • , Adam Doupé
  • , Yan Shoshitaishvili
  • , Ziming Zhao
  • , Gail Joon Ahn
  • Arizona State University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

29 Scopus citations

Abstract

Network Management is a critical process for an enterprise to con-gure and monitor the network devices using cost eective methods. It is imperative for it to be robust and free from adversarial or accidental security aws. With the advent of cloud computing and increasing demands for centralized network control, conventional management protocols like SNMP appear inadequate and newer techniques like NMDA and NETCONF have been invented. However, unlike SNMP which underwent improvements concentrating on security, the new data management and storage techniques have not been scrutinized for the inherent security aws. In this paper, we identify several vulnerabilities in the widely used critical infrastructures which leverage the Network Management Datastore Architecture design (NMDA). Software Dened Networking (SDN), a proponent of NMDA, heavily relies on its datastores to program and manage the network. We base our research on the security challenges put forth by the existing datastore’s design as implemented by the SDN controllers. The vulnerabilities identied in this work have a direct impact on the controllers like OpenDayLight, Open Network Operating System and their proprietary implementations (by CISCO, Ericsson, RedHat, Brocade, Juniper, etc). Using our threat detection methodology, we demonstrate how the NMDA-based implementations are vulnerable to attacks which compromise availability, integrity, and condentiality of the network. We nally propose defense measures to address the security threats in the existing design and discuss the challenges faced while employing these countermeasures.

Original languageEnglish
Title of host publicationCCS 2018 - Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages664-676
Number of pages13
ISBN (Electronic)9781450356930
DOIs
StatePublished - Oct 15 2018
Event25th ACM Conference on Computer and Communications Security, CCS 2018 - Toronto, Canada
Duration: Oct 15 2018 → …

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
ISSN (Print)1543-7221

Conference

Conference25th ACM Conference on Computer and Communications Security, CCS 2018
Country/TerritoryCanada
CityToronto
Period10/15/18 → …

Fingerprint

Dive into the research topics of 'AIM-SDN: Aacking information mismanagement in SDN-datastores'. Together they form a unique fingerprint.

Cite this