Authors:
Mattia Spina
;
Mauro Tropea
and
Floriano De Rango
Affiliation:
Department of Computer Engineering, Modeling, Electronics and Systems (DIMES), University of Calabria, via P. Bucci 39c, 87036 Rende, Italy
Keyword(s):
LLDP Attack, SDN, Mininet, Elliptic Curve Cryptography, RSA, HMAC, ECDSA, POX.
Abstract:
Software-Defined Networking (SDN) paradigm permits to have scalability and flexibility in the network management throughout a centralized control that has the global view of the network topology, but it introduces new security issues. In this paper, the Link Layer Discovery Protocol (LLDP) topological poisoning attack has been studied and analysed in order to provide possible mitigation solutions through the use of Mininet emulator and the POX controller. In particular, it is added to the LLDP protocol the integrity check using three different types of cryptographic algorithms such as Hash-based message authentication code (HMAC), Digital Signature Algorithm (DSA) using RSA and Elliptic Curve DSA (ECDSA). The performance evaluation of the proposal is provided considering a network topology where an attacker hijacks/impersonates an host already connected to the network.