作者: Seungsoo Lee , Seungwon Woo , Jinwoo Kim , Vinod Yegneswaran , Phillip Porras
DOI: 10.1109/INFOCOM41043.2020.9155378
关键词: Software-defined networking 、 Flow network 、 Computer security 、 Protocol (object-oriented programming) 、 Computer science 、 Test case 、 Network security policy 、 OpenFlow 、 Network security
摘要: At the foundation of every network security architecture lies premise that formulated flow policies are reliably deployed and enforced by infrastructure. However, software-defined networks (SDNs) add a particular challenge to satisfying this premise, as for SDNs pol-icy implementation spans multiple applications abstraction layers across SDN stack. In paper, we focus on question how automatically identify cases in which stack fails prevent policy inconsistencies from arising among these components. This is rather essential, when such arise implications reliability devastating. We present AudiSDN, an automated fuzz-testing framework designed formulate test can OpenFlow networks, most prevalent protocol used today. also results applying AudiSDN two widely controllers, Floodlight ONOS. fact, our have led filing 3 separate CVE reports. believe approach presented paper applicable breadth platforms today, its broader usage will help address serious but yet understudied pragmatic concern.