메뉴 건너뛰기




Volumn , Issue , 2018, Pages

Taking control of SDN-based cloud systems via the data plane

Author keywords

Attacker models; Cloud security; Data plane security; MPLS; Network isolation; Network virtualization; NFV; Open vSwitch; OpenStack; Packet parsing; ROP; SDN; Virtual switches

Indexed keywords

MULTIPROTOCOL LABEL SWITCHING; NETWORK FUNCTION VIRTUALIZATION; PLATFORM AS A SERVICE (PAAS);

EID: 85049390536     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/3185467.3185468     Document Type: Conference Paper
Times cited : (38)

References (97)
  • 1
    • 84876928048 scopus 로고    scopus 로고
    • Accessed: 02-06
    • [n. d.]. ROPGadget Tool. https://github.com/JonathanSalwan/ROPgadget/tree/master. ([n. d.]). Accessed: 02-06-2016.
    • (2016) ROPGadget Tool.
  • 3
    • 84994681700 scopus 로고    scopus 로고
    • 2013). Accessed: 27-01-2017
    • 2013. Huawei HG8245 backdoor and remote access. http://websec.ca/advisories/view/Huawei-web-backdoor-and-remote-access. (2013). Accessed: 27-01-2017.
    • (2013) Huawei HG8245 Backdoor and Remote Access.
  • 4
    • 85049209592 scopus 로고    scopus 로고
    • 2014). Accessed: 27-01-2017
    • 2014. Netis Routers Leave Wide Open Backdoor. http://blog.trendmicro.com/trendlabs-security-intelligence/netisrouters- leave-wide-open-backdoor/. (2014). Accessed: 27-01-2017.
    • (2014) Netis Routers Leave Wide Open Backdoor.
  • 5
    • 84961331917 scopus 로고    scopus 로고
    • 2014). Accessed: 27-01-2017
    • 2014. Snowden: The NSA planted backdoors in Cisco products. http://www.infoworld.com/article/2608141/internet-privacy/snowden-the-nsa-planted\-backdoors-in-cisco-products.html. (2014). Accessed: 27-01-2017.
    • (2014) Snowden: The NSA Planted Backdoors in Cisco Products.
  • 6
    • 85017515496 scopus 로고    scopus 로고
    • 2016). Accessed: 27-01-2017
    • 2016. OpenStack Security Guide. http://docs.openstack.org/securityguide. (2016). Accessed: 27-01-2017.
    • (2016) OpenStack Security Guide.
  • 7
    • 85034247912 scopus 로고    scopus 로고
    • 2016
    • 2016. What is Openstack? https://www.openstack.org/software. (2016).
    • (2016) What is Openstack?
  • 13
    • 85056400995 scopus 로고    scopus 로고
    • BESS Comitters. 2017). Accessed: 09-05-2017
    • BESS Comitters. 2017. BESS (Berkeley Extensible Software Switch). https://github.com/NetSys/bess. (2017). Accessed: 09-05-2017.
    • (2017) BESS (Berkeley Extensible Software Switch
  • 15
    • 84995436872 scopus 로고    scopus 로고
    • A systematic analysis of the juniper dual EC incident
    • Report 2016/376. (2016
    • Stephen Checkoway et al. 2016. A Systematic Analysis of the Juniper Dual EC Incident. Cryptology ePrint Archive, Report 2016/376. (2016).
    • (2016) Cryptology ePrint Archive
    • Checkoway, S.1
  • 17
    • 84966309009 scopus 로고    scopus 로고
    • All your cluster-grids are belong to us: Monitoring the (in)security of infrastructure monitoring systems
    • Andrei Costin. 2015. All your cluster-grids are belong to us: Monitoring the (in)security of infrastructure monitoring systems. In Proc. IEEE Communications and Network Security (CNS). 550-558. https://doi.org/10.1109/CNS.2015.7346868
    • (2015) Proc. IEEE Communications and Network Security (CNS , pp. 550-558
    • Costin, A.1
  • 18
    • 85084160243 scopus 로고    scopus 로고
    • StackGuard: Automatic adaptive detection and prevention of buffer-overflow attacks
    • Crispin Cowan et al. 1998. StackGuard: Automatic Adaptive Detection and Prevention of Buffer-overflow Attacks. In Proc. Usenix Security Symp. 5-5.
    • (1998) Proc. Usenix Security Symp , pp. 5
    • Cowan, C.1
  • 22
    • 85049400374 scopus 로고    scopus 로고
    • Cloud-trust - A security assessment model for infrastructure as a service (IaaS) clouds
    • 2017)
    • Dan Gonzales et al. 2017. Cloud-Trust - a Security Assessment Model for Infrastructure as a Service (IaaS) Clouds. Proc. IEEE Conference on Cloud Computing PP, 99 (2017), 1-1.
    • (2017) Proc. IEEE Conference on Cloud Computing , vol.99 , pp. 1
    • Gonzales, D.1
  • 23
    • 84891773625 scopus 로고    scopus 로고
    • The road to SDN
    • December 2013
    • Nick Feamster, Jennifer Rexford, and Ellen Zegura. 2013. The Road to SDN. Queue 11, 12 (December 2013).
    • (2013) Queue , vol.11 , pp. 12
    • Feamster, N.1    Rexford, J.2    Zegura, E.3
  • 28
    • 79953657305 scopus 로고    scopus 로고
    • Understanding cloud computing vulnerabilities
    • (March 2011)
    • Bernd Grobauer, Tobias Walloschek, and Elmar Stocker. 2011. Understanding Cloud Computing Vulnerabilities. Proc. IEEE Security & Privacy (S&P) 9, 2 (March 2011), 50-57. https://doi.org/10.1109/MSP.2010.115
    • (2011) Proc. IEEE Security & Privacy (S&P) , vol.9 , Issue.2 , pp. 50-57
    • Grobauer, B.1    Walloschek, T.2    Stocker, E.3
  • 32
    • 85049405938 scopus 로고    scopus 로고
    • Intel. 2015
    • Intel. 2015. Enabling NFV to Deliver on its Promise. https://www-ssl.intel.com/content/www/us/en/communications/nfv-packet-processing-brief .html. (2015).
    • (2015) Enabling NFV to Deliver on its Promise.
  • 33
    • 85014838358 scopus 로고    scopus 로고
    • Softflow: A middlebox architecture for open vswitch
    • Ethan J Jackson et al. 2016. Softflow: A middlebox architecture for open vswitch. In Usenix Annual Technical Conference (ATC). 15-28.
    • (2016) Usenix Annual Technical Conference (ATC , pp. 15-28
    • Jackson, E.J.1
  • 34
    • 85013623251 scopus 로고
    • Congestion avoidance and control
    • Van Jacobson
    • Van Jacobson. 1988. Congestion avoidance and control. In ACM Computer Communication Review (CCR), Vol. 18. 314-329.
    • (1988) ACM Computer Communication Review (CCR) , vol.18 , pp. 314-329
  • 35
    • 84891618095 scopus 로고    scopus 로고
    • B4: Experience with a globally-deployed software defined wan
    • Sushant Jain et al. 2013. B4: Experience with a Globally-deployed Software Defined Wan. In Proc. ACM SIGCOMM. 3-14.
    • (2013) Proc. ACM SIGCOMM , pp. 3-14
    • Jain, S.1
  • 38
    • 85049393223 scopus 로고    scopus 로고
    • Version 0. Rev. 0.1. Apr 23 (2010)
    • Daya Kamath et al. 2010. Edge virtual Bridge Proposal, Version 0. Rev. 0.1. Apr 23 (2010), 1-72.
    • (2010) Edge Virtual Bridge Proposal , pp. 1-72
    • Kamath, D.1
  • 49
    • 85049406001 scopus 로고    scopus 로고
    • Time for an SDN sequel?
    • Version 2. 2014). Accessed: 27-01-2017
    • Craig Matsumoto. 2014. Time for an SDN Sequel? Scott Shenker Preaches SDN Version 2. https://www.sdxcentral.com/articles/news/scott-shenker-preaches-revised-sdn-sdnv2/2014/10/. (2014). Accessed: 27-01-2017.
    • (2014) Scott Shenker Preaches SDN
    • Matsumoto, C.1
  • 51
    • 68649129121 scopus 로고    scopus 로고
    • OpenFlow: Enabling innovation in campus networks
    • 2008)
    • Nick McKeown et al. 2008. OpenFlow: Enabling innovation in campus networks. ACM Computer Communication Review (CCR) 38, 2 (2008), 69-74.
    • (2008) ACM Computer Communication Review (CCR) , vol.38 , Issue.2 , pp. 69-74
    • Nick McKeown1
  • 52
    • 84967218989 scopus 로고    scopus 로고
    • Microsoft. 2013). Accessed: 27-01-2017
    • Microsoft. 2013. Hyper-V Virtual Switch Overview. https://technet.microsoft.com/en-us/library/hh831823(v=ws.11) .aspx. (2013). Accessed: 27-01-2017.
    • (2013) Hyper-V Virtual Switch Overview.
  • 54
    • 85033567481 scopus 로고    scopus 로고
    • Scalable highperformance elastic software OpenFlow switch in userspace for widearea network
    • 2014)
    • Yoshihiro Nakajima, Tomoya Hibi, Hirokazu Takahashi, Hitoshi Masutani, Katsuhiro Shimano, and Masaki Fukui. 2014. Scalable highperformance elastic software OpenFlow switch in userspace for widearea network. USENIX Open Networking Summit (2014), 1-2.
    • (2014) USENIX Open Networking Summit , pp. 1-2
    • Nakajima, Y.1    Hibi, T.2    Takahashi, H.3    Masutani, H.4    Shimano, K.5    Fukui, M.6
  • 57
    • 84876916044 scopus 로고    scopus 로고
    • 2012). Accessed: 27-01-2017
    • Mathias Payer. 2012. Too much PIE is bad for performance. http://e-collection.library.ethz.ch/eserv/eth:5699/eth-5699-01.pdf. (2012). Accessed: 27-01-2017.
    • (2012) Too much PIE is bad for performance.
    • Payer, M.1
  • 65
    • 85049400945 scopus 로고    scopus 로고
    • Abusing software defined networks
    • Gregory Pickett. 2014. Abusing software defined networks. Black Hat EU (2014).
    • (2014) Black Hat EU (2014)
    • Pickett, G.1
  • 66
    • 84893494247 scopus 로고    scopus 로고
    • Removing roadblocks from SDN: OpenFlow software switch performance on Intel DPDK
    • IEEE
    • Gergely Pongrácz, László Molnár, and Zoltán Lajos Kis. 2013. Removing roadblocks from SDN: OpenFlow software switch performance on Intel DPDK. In European Workshop on Software Defined Networking. IEEE, 62-67.
    • (2013) European Workshop on Software Defined Networking. , pp. 62-67
    • Pongrácz, G.1    Molnár, L.2    Kis, Z.L.3
  • 72
    • 85077130189 scopus 로고    scopus 로고
    • Netmap: A novel framework for fast packet I/O
    • Luigi Rizzo. 2012. Netmap: A novel framework for fast packet I/O. In Usenix Annual Technical Conference (ATC). 101-112.
    • (2012) Usenix Annual Technical Conference (ATC , pp. 101-112
    • Rizzo, L.1
  • 73
    • 84871992801 scopus 로고    scopus 로고
    • VALE, a switched ethernet for virtual machines
    • Luigi Rizzo and Giuseppe Lettieri. 2012. VALE, a Switched Ethernet for Virtual Machines. In Proc. ACM CoNEXT. 61-72.
    • (2012) Proc. ACM CoNEXT , pp. 61-72
    • Rizzo, L.1    Lettieri, G.2
  • 74
    • 85049410740 scopus 로고    scopus 로고
    • 2016). Accessed: 27-01-2017
    • Robin G. 2016. Open vSwitch with DPDK Overview. https://software.intel.com/en-us/articles/open-vswitch-withdpdk- overview. (2016). Accessed: 27-01-2017.
    • (2016) Open vSwitch with DPDK Overview.
    • Robin, G.1
  • 81
    • 85049408511 scopus 로고    scopus 로고
    • 2017). Accessed: 29-01-2018
    • Bhargava Shastry. 2017. Fuzzing Open vSwitch. https://bshastry.github.io/2017/07/24/Fuzzing-OpenvSwitch.html. (2017). Accessed: 29-01-2018.
    • (2017) Fuzzing Open vSwitch.
    • Shastry, B.1
  • 86
    • 84888378420 scopus 로고    scopus 로고
    • A primitive for revealing stealthy peripheralbased attacks on the computing platform's main memory
    • Springer
    • Patrick Stewin. 2013. A primitive for revealing stealthy peripheralbased attacks on the computing platform's main memory. In Proc. RAID Recent Advances in Intrusion Detection. Springer, 1-20.
    • (2013) Proc. RAID Recent Advances in Intrusion Detection. , pp. 1-20
    • Stewin, P.1
  • 89
  • 91
    • 85037036625 scopus 로고    scopus 로고
    • A snapshot of Openstack users' attitudes and deployments
    • Apr(Apr 2016
    • Heidi Joy Tretheway et al. Apr 2016. A snapshot of Openstack users' attitudes and deployments. Openstack User Survey (Apr 2016).
    • (2016) Openstack User Survey
    • Tretheway, H.J.1
  • 94
    • 85049410488 scopus 로고    scopus 로고
    • VMware.Update 1 Release Notes.2009). Accessed: 27-01-2017
    • VMware. 2009. VMware ESX 4.0 Update 1 Release Notes. https://www.vmware.com/support/vsphere4/doc/vspesx40u1relnotes.html. (2009). Accessed: 27-01-2017.
    • (2009) VMware ESX 4.0
  • 95
    • 85049409444 scopus 로고    scopus 로고
    • VPP Comitters.2017). Accessed: 09-05-2017
    • VPP Comitters. 2017. What is VPP? https://wiki.fd.io/view/VPP/WhatisVPP%3F. (2017). Accessed: 09-05-2017.
    • (2017) What is VPP?


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.