Header menu link for other important links
X
Mitigation of security attacks in the SDN data plane using P4-enabled switches
, Niranjhana Narayanan, Ganesh C. Sankaran
Published in IEEE
2019
Volume: 2019-December
   
Abstract
This paper presents a study and demonstration of some of the commonly seen internal security attacks and related countermeasures using P4, a dataplane programming language. The idea is that the vulnerabilities arising in programmable data planes are sufficiently mitigated with this P4 implementation. This also provides users with the flexibility to add or drop security features in the deployed switches, better visibility into the defense system owing to its open source nature and the portability of these P4 programs across many different vendors and devices. We evaluate our P4 code on software and hardware switches to detect IP-address spoofing attacks. The results show that attack packets are always detected and dropped, while the throughput remains unaffected and nearly constant across varying fractions of malicious packets injected in the network. © 2019 IEEE.
About the journal
JournalData powered by TypesetInternational Symposium on Advanced Networks and Telecommunication Systems, ANTS
PublisherData powered by TypesetIEEE
Open AccessNo