Routing-Verification-as-a-Service (RVaaS): Trustworthy Routing Despite Insecure Providers

Routing-Verification-as-a-Service (RVaaS): Trustworthy Routing Despite Insecure Providers

Abstract

Computer networks today typically do not provide any mechanisms to the users to learn, in a reliable manner, which paths have (and have not!) been taken by their packets. Rather, it seems inevitable that as soon as a packet leaves the network card, the user is forced to trust the network provider to forward the packets as expected or agreed upon. This can be undesirable, especially in the light of today’s trend toward more programmable networks: after a successful cyber attack on the network management system or Software-Defined Network (SDN) control plane, an adversary in principle has complete control over the network. This paper presents a low-cost and efficient solution to detect misbehaviors and ensure trustworthy routing over untrusted or insecure providers, in particular providers whose management system or control plane has been compromised (e.g., using a cyber attack). We propose Routing-Verification-as-a-Service (RVaaS): RVaaS offers clients a flexible interface to query information relevant to their traffic, while respecting the autonomy of the network provider. RVaaS leverages key features of OpenFlow-based SDNs to combine (passive and active) configuration monitoring, logical data plane verification and actual in-band tests, in a novel manner.

Grafik Top
Authors
  • Schiff, Liron
  • Thimmaraju, Kashyap
  • Schmid, Stefan
Grafik Top
Supplemental Material
Shortfacts
Category
Paper in Conference Proceedings or in Workshop Proceedings (Paper)
Event Title
IEEE/IFIP DSN Workshop on Dependability Issues on SDN and NFV (DISN)
Divisions
Communication Technologies
Subjects
Informatik Allgemeines
Event Location
Toulouse, France
Event Type
Workshop
Event Dates
June 2016
Date
2016
Export
Grafik Top