4.5 SDN Security Attack Prevention 99
guarantees, or route modifications. The ISP authenticates these
requests, processes them, and implements them by setting up rules
in its OpenFlow switches. In case of queries, the ISP returns the
requested information to the remote customer network. This reply is
also protected through cryptographic means to ensure authenticity
and freshness. Let us denote by SENSS ISP an ISP that deploys SENSS.
We use the same definition of flow as does OpenFlow and we define
a tag to be a unique identifier of an AS that neighbors an ISP that
deploys SENSS. A traffic aggregate is a combination of flow, tag, and
direction (IN or OUT) fields.
Table 4.1 defines SENSS messages from the customer (victim network) to the provider (SENSS ISP) and replies or actions taken by the
provider. A traffic query asks about the distribution of traffic across
ASes that neighbor with a SENSS ISP. It specifies the traffic aggregate of interest and the duration of observation. The ISP returns the
list of packets or bytes sent by or sent to each neighbor. This helps
SENSS customer trace back its traffic and identify best points to deploy
mitigation.
• Route query asks a SENSS ISP about the best route it has to the customer’s prefix. The provider replies with a full AS path. This enables
the customer to diagnose route detour attacks and blackholing and
to mitigate them. The victim networks can also ask the SENSS ISP
Table 4.1 SENSS messages from the customer to the provider and replies/actions
by the provider.
Message
Fields
Reply/action
Traffic query
Aggregate, duration A list of direction> for the aggregate
Route query
Prefix
AS paths from the provider to the
prefix
Traffic filter
Aggregate
Filter all traffic matching the
aggregate
Bandwidth guarantee Aggregate, bw
Guarantee bandwidth bw for
traffic matching the aggregate
Route demotion
Prefix,
Demote route to prefix that has
specified AS path segment
Route modification
Prefix, ,

Modify the false AS path segment
to the correct one
Précédent

- 119/195

Suivant