Journal on Communications ›› 2021, Vol. 42 ›› Issue (7): 70-83.doi: 10.11959/j.issn.1000-436x.2021108

• Papers • Previous Articles     Next Articles

Port address overloading based packet forwarding verification in SDN

Ping WU, Chaowen CHANG, Yingying MA   

  1. Department of Cryptogram Engineering, Information Engineering University, Zhengzhou 450004, China
  • Revised:2021-03-31 Online:2021-07-25 Published:2021-07-01
  • Supported by:
    The National Natural Science Foundation of China(61572517)

Abstract:

Aiming at the problem that the existing forwarding verification mechanisms in software-defined networking (SDN) incur significant communication overhead caused by embedding additional packet fields, a packet forwarding verification mechanism based on port address overloading was proposed, which key idea was the ingress switch implemented port address overloading by reconstructing port and address of packet, downstream switches executed packet probabilistic verification based on overloading port address, and the controller acquired valid and invalid packet statistics of node verification in the path and localized anomaly.Anomaly detection threshold of malicious injecting and dropping packets was presented by theoretical analysis.Finally, the proposed scheme was implemented and evaluated.Experiments demonstrate the proposed scheme achieves efficient forwarding and effective anomaly localization with less than 10% of additional forwarding delays and less than 8% of throughput degradation.

Key words: software-defined networking, path vector, port address overloading, probabilistic verification, anomaly localization

CLC Number: 

No Suggested Reading articles found!