Model of Distributed Attacks in Program-Configurable Communication Networks

Authors

  • Yu. Yu. Kolyadenko Kharkiv National University of Radio Electronics
  • I. G. Lukinov Kharkiv National University of Radio Electronics; Kharkiv State Regional Scientific Technical Center of Technical Information Protection

DOI:

https://doi.org/10.14529/ctcr170304

Keywords:

SDN-network, controller, switch, OpenFlow protocol, information security, attacks, queuing theory

Abstract

It is shown that the architecture of SDN is not without potential vulnerabilities in terms of information security. The controller as a key component in the management of the entire SDN infrastructure is the most vulnerable element, the attack on which can entail consequences that are critical for the entire infrastructure. The main threats arising from network devices operating on the principle of a program-configurable network are variations of such attacks as “denial of service”, replacement of the controller, and so on.

The SDN-network's reaction to the flows of various packets, including attacks, is considered as the functioning of some queuing system that processes processing requirements for packets. A mathematical model of the SDN-network in the form of a queuing system was developed. A mathematical dependence of the average number of applications is obtained upon the appearance of attacks. The graphs of the average number of applications are obtained in the presence of attacks against the probability of packet loss. Advantages of the proposed model are the possibility of timely (early) detection of an attack, its ability to adapt to the real parameters of the network.

Author Biographies

Yu. Yu. Kolyadenko, Kharkiv National University of Radio Electronics

д-р техн. наук, профессор, профессор кафедры инфокоммуникационной инженерии

I. G. Lukinov, Kharkiv National University of Radio Electronics; Kharkiv State Regional Scientific Technical Center of Technical Information Protection

аспирант кафедры инфокоммуникационной инженерии; инженер

References

Захаров, А.А. Аспекты информационной безопасности архитектуры SDN / А.А. Захаров, Е.Ф. Попов, М.М. Фучко // Вестник СибГУТИ. – 2016. – № 1. – С. 83–92.

Openflow: enabling innovation in campus networks / N. McKeown, T. Anderson, H. Balakrishnan et al. // ACM SIGCOMM Computer Communication Review. – 2008. – Vol. 38, iss. 4. – Р. 69–74. DOI: 10.1145/1355734.1355746

OpenFlow Switch Specification Ver 1.5.1, 2016 – https://www.opennetworking.org/images/stories/downloads/sdnresources/ onf-specifications/openflow/openflow-switch-v1.5.1.pdf (дата обращения: 11.01.2016).

Партыка, Т.Л. Информационная безопасность: учеб. пособие для студентов учреждений сред. проф. образования / Т.Л. Партыка, И.И. Попов. – М.: ФОРУМ: ИНФРА-М. – 2002. − 368 с.

Лукацкий, А. Информационная безопасность 2015 / А. Лукацкий // ИТ-безопасность. Стандарты. Средства защиты. Мероприятия. – 2013. – № 12. – С. 64–69.

Ложковский, А.Г. Теория массового обслуживания в телекоммуникациях: учеб. / А.Г. Ложковский. – Одесса: ОНАС им. А.С. Попова, 2012. – 112 с.

Ложковский, А.Г. Моделирование многоканальной системы обслуживания с организацией очереди / А.Г. Ложковский, Н.С. Салманов, О.В. Вербанов // Восточно-Европейский журнал передовых технологий. – 2007. – № 3/6 (27). – С. 72–76.

Корнышев, Ю.Н. Теория распределения информации: учеб. пособие для вузов / Ю.Н. Корнышев, Г.Л. Фань. – М.: Радио и Связь, 1985. – 184 с.

Published

2017-09-07

Issue

Section

Communication Technologies and Systems