2017 16th Annual Mediterranean Ad Hoc Networking Workshop (Med-Hoc-Net) 2017
DOI: 10.1109/medhocnet.2017.8001642
|View full text |Cite
|
Sign up to set email alerts
|

Limitations of openflow topology discovery protocol

Abstract: Abstract-OpenFlow Discovery Protocol (OFDP) is the defacto protocol used by OpenFlow controllers to discover the underlying topology. In this paper, we show that OFDP has some serious security, efficiency and functionality limitations that make it non suitable for production deployments. Instead, we briefly introduce sOFTD, a new discovery protocol with a built-in security characteristics and which is more efficient than traditional OFDP.

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
19
0

Year Published

2018
2018
2022
2022

Publication Types

Select...
4
2
1

Relationship

1
6

Authors

Journals

citations
Cited by 41 publications
(19 citation statements)
references
References 5 publications
0
19
0
Order By: Relevance
“…1) Security of OFDP: The authors of [21], [22], [23], and [24] show that OFDP is vulnerable to spoofing attacks. Injected LLDP control messages may create fake links that redirect traffic to the host of an attacker.…”
Section: Optimized Variants Of Ofdpmentioning
confidence: 99%
See 1 more Smart Citation
“…1) Security of OFDP: The authors of [21], [22], [23], and [24] show that OFDP is vulnerable to spoofing attacks. Injected LLDP control messages may create fake links that redirect traffic to the host of an attacker.…”
Section: Optimized Variants Of Ofdpmentioning
confidence: 99%
“…Injected LLDP control messages may create fake links that redirect traffic to the host of an attacker. The authors of [23] show that OFDP is additionally vulnerable to controller fingerprinting, switch fingerprinting, and LLDP flooding attacks. The authors of [24] show that OFDP is vulnerable to replay attacks of LLDP packets that result in incorrect link information of the topology.…”
Section: Optimized Variants Of Ofdpmentioning
confidence: 99%
“…Such protocol is based on the exchange of Link Layer Discovery Protocol (LLDP) packets containing chassis‐ID and port‐ID identifiers in their payload, so that the controller can use this information, along with other metadata, to map the underlying links at the control level. In this regard, various analyses (see, eg, other related works) have remarked the vulnerabilities of using OFDP, proposing both enhancements to the current protocol and other methods for accomplishing link discovery in these types of networks. Specifically, the work of Pakzad et al presents an enhanced version of the protocol with less LLDP message exchanges (OFDPv2).…”
Section: Link Discovery In Sdn‐based Optical Networkmentioning
confidence: 99%
“…Specifically, the work of Pakzad et al 13 presents an enhanced version of the protocol with less LLDP message exchanges (OFDPv2). Then, the work of Azzouni et al 14 presents the secure OF topology discovery that adds security to the protocol by introducing minimal changes to the OF switch design. Finally, the one work reported by Alharbi et al 15 proposes to enhance the authentication of LLDP packets by using hash-based message authentication code.…”
Section: Link Discovery In Sdn-based Optical Networkmentioning
confidence: 99%
“…One of the controller's duties is to perform an accurate, secure and near real time topology discovery to provide management applications with an up-to-date view of the network topology. However, all current SDN controllers perform topology discovery using OpenFlow Discovery Protocol (OFDP), which is far from being secure and efficient [3]. Figure 1 shows how OFDP works; To discover the unidirectional link s1 → s2, the controller encapsulates a LLDP packet in a packet-out message and sends it to s1.…”
Section: Introductionmentioning
confidence: 99%