Taking Control of SDN-based Cloud Systems via the Data Plane

Conference Paper (2018)
Author(s)

Kashyap Thimmaraju (Technical University of Berlin)

Bhargava Shastry (Technical University of Berlin)

Tobias Fiebig (TU Delft - Information and Communication Technology)

Felicitas Hetzelt (Technical University of Berlin)

Jean-Pierre Seifert (Technical University of Berlin)

Anja Feldmann (Max Planck Institut für Informatik)

Stefan Schmid (University of Vienna)

Research Group
Information and Communication Technology
Copyright
© 2018 Kashyap Thimmaraju, Bhargava Shastry, T. Fiebig, Felicitas Hetzelt, Jean-Pierre Seifert, Anja Feldmann, Stefan Schmid
DOI related publication
https://doi.org/10.1145/3185467.3185468
More Info
expand_more
Publication Year
2018
Language
English
Copyright
© 2018 Kashyap Thimmaraju, Bhargava Shastry, T. Fiebig, Felicitas Hetzelt, Jean-Pierre Seifert, Anja Feldmann, Stefan Schmid
Research Group
Information and Communication Technology
Pages (from-to)
1-15
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Virtual switches are a crucial component of SDN-based cloud systems, enabling the interconnection of virtual machines in a flexible and “software-defined” manner. This paper raises the alarm on the security implications of virtual switches. In particular, we show that virtual switches not only increase the attack surface of the cloud, but virtual switch vulnerabilities can also lead to attacks of much higher impact compared to traditional switches. We present a systematic security analysis and identify four design decisions which introduce vulnerabilities. Our findings motivate us to revisit existing threat models for SDN-based cloud setups, and introduce a new attacker model for SDN-based cloud systems using virtual switches.

Files

Sosr18.pdf
(pdf | 1.05 Mb)
Unspecified