Prelude: Ensuring Inter-Domain Loop-Freedom in SDN-Enabled Networks

06/25/2018
by   Arnaud Dethise, et al.
0

Software-Defined-eXchanges (SDXes) promise to tackle the timely quest of bringing improving the inter-domain routing ecosystem through SDN deployment. Yet, the naive deployment of SDN on the Internet raises concerns about the correctness of the inter-domain data-plane. By allowing operators to deflect traffic from the default BGP route, SDN policies are susceptible of creating permanent forwarding loops invisible to the control-plane. In this paper, we propose a system, called Prelude, for detecting SDN-induced forwarding loops between SDXes with high accuracy without leaking the private routing information of network operators. To achieve this, we leverage Secure Multi-Party Computation (SMPC) techniques to build a novel and general privacy-preserving primitive that detects whether any subset of SDN rules might affect the same portion of traffic without learning anything about those rules. We then leverage that primitive as the main building block of a distributed system tailored to detect forwarding loops among any set of SDXes. We leverage the particular nature of SDXes to further improve the efficiency of our SMPC solution. The number of valid SDN rules, i.e., not creating loops, rejected by our solution is 100x lower than previous privacy-preserving solutions, and also provides better privacy guarantees. Furthermore, our solution naturally provides network operators with some hindsight on the cost of the deflected paths.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/12/2018

SDPMN: Privacy Preserving MapReduce Network Using SDN

MapReduce is a popular programming model and an associated implementatio...
research
04/09/2020

Formal Modelling and Verification of Software Defined Network

In cloud computing, software-defined network (SDN) gaining more attentio...
research
09/19/2018

Privacy-Preserving DDoS Attack Detection Using Cross-Domain Traffic in Software Defined Networks

Existing distributed denial-of-service attack detection in software defi...
research
01/14/2018

Software Defined Networks based Smart Grid Communication: A Comprehensive Survey

Software defined networks (SDN) has been proposed to monitor and manage ...
research
11/02/2019

SDN Enhanced Ethernet VPN for Data Center Interconnect

Ethernet Virtual Private Network (EVPN) is an emerging technology that a...
research
06/07/2019

Identifying Operational Data-paths in Software Defined Networking Driven Data-planes

In this paper, we propose an approach that relies on distributed traffic...
research
06/07/2019

Verifying SDN Data Path Requests

Software Defined Networking (SDN) is a pillar technology for network vir...

Please sign up or login with your details

Forgot password? Click here to reset