Journal on Communications ›› 2022, Vol. 43 ›› Issue (3): 88-100.doi: 10.11959/j.issn.1000-436x.2022047

• Papers • Previous Articles     Next Articles

Address overloading-based packet forwarding verification in SDN

Ping WU1, Chaowen CHANG1, Zhibin ZUO2, Yingying MA1   

  1. 1 Department of Cryptogram Engineering, Information Engineering University, Zhengzhou 450004, China
    2 College of Information Science and Engineering, Henan University of Technology, Zhengzhou 450001, China
  • Revised:2021-12-26 Online:2022-03-25 Published:2022-03-01
  • Supported by:
    The National Natural Science Foundation of China(61572517);Science and Technology Project of Henan Province(222102210070)

Abstract:

Aiming at the problem that the most existing forwarding verification mechanisms in software-defined network (SDN) verified packets hop-by-hop by incorporating new secure communication protocols, which incurred significant computation and communication overhead, an address overloading-based forwarding verification mechanism was proposed.The flow runtime was divided into consecutive random intervals by the ingress switch via overloading address fields of packet, basing on overloading address, packets were forwarded by each subsequent switch, and the controller sampled the packets forwarded by ingress and egress switch in the interval to detect abnormal behavior on the path.Finally, the proposed mechanism and simulation network was implemented and evaluated.Experiments show that the mechanism achieves efficient forwarding and effective anomaly detection with less than 8% of additional forwarding delays.

Key words: software-defined networking, address overloading, hash-based sampling, anomaly detection

CLC Number: 

No Suggested Reading articles found!