Proceedings of the 2021 ACM International Workshop on Software Defined Networks &Amp; Network Function Virtualization Security 2021
DOI: 10.1145/3445968.3452092
|View full text |Cite
|
Sign up to set email alerts
|

A Survey on the Verification of Adversarial Data Planes in Software-Defined Networks

Abstract: As network policies are becoming increasingly nuanced and complex, so too are the mechanisms required to ensure that the network is functioning as intended. In particular, since the dawn of softwaredefined networking and the shift towards high-level descriptions of intended network policy, traditional tools such as ping and traceroute have been insufficient to test that complex data plane configurations have been correctly implemented. As a result, novel data plane verification solutions have been proposed tha… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2

Citation Types

0
2
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
4
1

Relationship

2
3

Authors

Journals

citations
Cited by 6 publications
(2 citation statements)
references
References 45 publications
0
2
0
Order By: Relevance
“…Equally, many compromised switch detection mechanisms have been proposed [9], that, in general, attempt to detect compromise by injecting test packets through the data plane and comparing their forwarding to expected behaviour.…”
Section: Introductionmentioning
confidence: 99%
“…Equally, many compromised switch detection mechanisms have been proposed [9], that, in general, attempt to detect compromise by injecting test packets through the data plane and comparing their forwarding to expected behaviour.…”
Section: Introductionmentioning
confidence: 99%
“…State-of-the-art solutions to detecting compromised data plane devices [4] have trended towards monitoring how the devices forward crafted sets of probe packets, raising an alert if this differs from the intended behaviour. Of course, testing the forwarding behaviour of every possible packet is infeasible, particularly in stateful networks, where naive testing can take 20 hours [13].…”
Section: Introductionmentioning
confidence: 99%