VIET NAM NATIONAL UNIVERSITY - HO CHI MINH CITY HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY HO QUANG CHI BAO BUILDING A FRAMEWORK FOR SECURED OPENFLOW SWITCH BASED ON FPGA XÂY DỰNG FRAMEWORK CHO SECURED OPENFLOW SWITCH TRÊN PHẦN CỨNG FPGA MAJOR: COMPUTER SCIENCE MAJOR ID: 60.01 MASTER THESIS HO CHI MINH CITY - DEC 2016 VIET NAM NATIONAL UNIVERSITY - HO CHI MINH CITY HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY HO QUANG CHI BAO BUILDING A FRAMEWORK FOR SECURED OPENFLOW SWITCH BASED ON FPGA XÂY DỰNG FRAMEWORK CHO SECURED OPENFLOW SWITCH TRÊN PHẦN CỨNG FPGA MAJOR: COMPUTER SCIENCE MAJOR ID: 60.01 MASTER THESIS SCIENTIFIC ADVISOR Assoc. TRAN NGOC THINH HO CHI MINH CITY - DEC 2016 THE THESIS IS COMPLETED AT HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY - VNU HCM Signature Scientific advisor: Assoc. Tran Ngoc Thinh. The first reviewer: Dr.
Pham Hoang Anh. The second reviewer: Assoc. Tran Manh Ha. The master thesis is defended at Ho Chi Minh City University of Technol- ogy (HCMUT), Viet Nam National University Ho Chi Minh City (VNU HCM) on.
The scientific council has been formed with members below: 1. Pham Tran Vu 2. Pham Quoc Cuong 3. Pham Hoang Anh 4.
Nguyen Manh Ha 5. Bui Trong Tu The master thesis has been approved by the chair of the scientific council and the dean of the Faculty of Computer Science and Engineering after corrected (if any). CHAIR DEAN Scientific Council Faculty of Computer Science and Engineering. VIET NAM NATIONAL UNIVERSITY - HCM SOCIALIST REPUBLIC OF VIET NAM HCMC UNIVERSITY OF TECHNOLOGY Independence - Liberty - Happiness —————- —————- THE MASTER THESIS RESPONSIBILITY Student: Ho Quang Chi Bao Student ID: 7140219 Day of Birth: Aug 25, 1980 Place of Birth: Tien Giang Major: Computer Science Major ID: 60.
THESIS NAME: Building a Framework for Secured OpenFlow Switch Based on FPGA II. RESPONSIBILITY AND CONTENT: The thesis responsibility aims to research and build a framework for detecting and preventing several kinds of network attack mechanism base on OpenFlow network. The research proposes a novel multi- core architecture associated with a high speed OpenFlow switch to make the such switch able to defend network attacking from the data plane of OpenFlow network architecture. THESIS IS DELIVERED ON: July 06th , 2015.
THESIS IS COMPLETED ON: Dec 4th , 2016. SCIENTIFIC ADVISOR: Assoc. Tran Ngoc Thinh. Ho Chi Minh City, December 04th , 2016 ADVISOR HEAD OF DEPARTMENT (Name and signature) (Name and signature).
DEAN Faculty of Computer Science and Engineering (Name and signature). A CKNOWLEDGMENTS First and foremost, I respectfully express my gratefulness to my advisor, Associate Professor Tran Ngoc Thinh for his warmly supports, taking the time from the be- ginning of my work to orient the research, and during step by step of the thesis process. My sincerely thanks also come to my teachers at Faculty of Computer Science & Engineering, Ho Chi Minh City University of Technology Ho who provided a lot of knowledge for me during my master course. To Computer Engineering Laboratory, I would also like to thank Nguyen Bao Quoc, Tran Thi Thuy Chau, Ngo Duc Minh and the many other individuals who take their efforts to help me in the prototype system implementation.
Moreover, I owe thanks to Doctor Cuong Pham-Quoc who has guided me and improved my skill a lot while writing papers and the thesis. Last but importantly, I would like to say thank you so much to my family, especially my Dad and my deceased Mum. I could not go far on my way without your encouragement. Again, I give my gratefulness to you, regarding the many sacrifices you made.
I am proud to be your son. Ho Chi Minh City, December 4t h , 2016 Ho Quang Chi Bao i A BSTRACT In recent years, Virtualization technology in the field of computer science and engineering has grown powerfully to meet the complexity increasing of customer’s demand while offering services for them. Especially, the advent of cloud com- puting has made the Information Technology industry be changing significantly. One important change is the improvement of IT infrastructure to offer a virtu- alized capacity at the network level for centralizing of system monitoring and management, quickly deploying services, and efficiently expanding a service.
Software Defined Networking (SDN) approach has been introduced to deal with these practical demands. SDN approach has offered several benefits comparing to the traditional net- work such as centralized controlling and monitoring, virtualizing and automatic at the network level. The main idea of SDN approach which is decoupling the control plane from the data plane makes SDN able to deal with almost require- ments that network infrastructure requests. However, alongside these benefits, SDN approach has conducted a big challenge involving security issues which make not only researchers but also network manufacturers consider carefully.
Especially in the scenario that there are more and more network attacks has been performed with the increasing in complexity of technology as well as the quan- tity of attack. By the idea centralized controlling at a controller, it becomes a single failure point in the network and an attractive target for cybers. In case of the controller has been attacked and collapsed, the whole network operating will be suspended and frozen immediately. Therefore, the protection of architectural SDN controller is a critical and urgent mission.
To protect the controller, in addi- tion to make it stronger and more reliable, the idea against network attacks from SDN data plane should be considered because it helps the network system able to defend itself earlier, to reduce the risk of whole network shutting-down. Stemming from this idea, we propose a secured OpenFlow-based switch ar- chitecture in this thesis. The architecture is a combination of OpenFlow Pro- cessing that routes packets according to the OpenFlow protocol and Security Processing that defends against network attacks. In particularly, the work of ii A BSTRACT iii the master’s thesis began proposing an architectural and constructing a kind of OpenFlow switches with integrated security functions to examine and evaluate the feasibility of the idea.
Base on experimental results the work keeps going to study and develop a framework to provide a utility for studying the security issues of OpenFlow network with the trend to defend attacking from the data plane. We have employed a reconfigurable hardware to deploy our ideas because of the flexibility and high performance of such devices to build a secured Open- Flow switch. By applying a multi-core architecture to implement secured cores, the proposed switch can work not only as a OpenFlow-based forwarding device but also as a network protection system. We implement our prototype switch on a Xilinx Virtex 5 xc5vtx240t FPGA de- vice.
In this prototype version, we integrate three different DDoS countermea- sure techniques, the Hop-Count Filter, Port Ingress/Egress Filter, and the SYN De- fender with two combination scenarios. The first scenario is the integrating of Hop-Count and Port Ingress/Egress Filter. In the second scenario, we combine the Port Ingress/Egress Filter with SYN Defender. The experimental results show that the switch in the first scenario achieves packet processing throughput by up to 9.87 Gbps in half duplex and 19.74 Gbps full duplex mode.
The switch can play with 100 % attacks detection rate and obtain a 0 % false positive rate and a 0 % false negative rate. However, the dropped packet rate of the overall system is approx 0.001 % because of the FIFO size limitation. In this scenario, the system consumes 39 % Look-Up Tables, 43 % Registers, and 64 % Block RAM of the FPGA device. In the second scenario, the hardware resources are consumed 41 % Look- Up Tables, 45 % Registers, and 61 % Block RAM.
Since the first implementation comprises many limitations, especially the timing score problem, the system can work only against SYN Flood attacking at ≈ 4 Gbps. In the case SYN Flood attack rate exceeds this threshold, these SYN packets can touch to the controller or the protected host. However, this problem depends on the place and route proce- dure of synthesis tool so we can optimize by several methods and techniques to improve the protecting capacity of the system. A BSTRACT iv Tóm Tắt Luận Văn Thạc Sĩ Trong những năm gần đây, công nghệ ảo hóa trong lĩnh vực khoa học và kỹ thuật máy tính đã phát triển ngày càng mạnh mẽ nhằm đáp ứng nhu cầu ngày càng phức tạp khi cung cấp dịch vụ cho khách hàng.
Đặc biệt với sự ra đời của dịch vụ điện toán đám mây - cloud computing đã thúc đẩy ngành công nghiệp IT có những chuyển biến lớn. Một trong những biến chuyển quan trọng chính là sự cải tiến hạ tầng công nghệ thông tin để đáp ứng nhu cầu ảo hóa ở mức network nhằm mục đích quản lý giám sát tập trung, triển khai dịch vụ nhanh chóng và mở rộng dịch vụ dễ dàng. Phương pháp tiếp cận mạng Software Defined-Networking (SDN) ra đời từ nhu cầu thực tiễn này. Từ khi xuất hiện, xu hướng tiếp cận SDN đem lại nhiều lợi ích hơn so với cách tiếp cận mạng truyền thống.
Với ý tưởng tách rời phần điều khiển (control plane) ra khỏi phần chuyển tiếp dữ liệu (data plane) đã giúp cho SDN có thể đáp ứng được những nhu cầu cấp thiết mà hạ tầng mạng hiện đại đòi hỏi. Tuy nhiên, bên cạnh những lợi ích đó, vấn đề bảo mật cho SDN trở thành thách thức lớn đối với những nhà nghiên cứu cũng như những nhà sản xuất thiết bị mạng trong bối cảnh thế giới ngày càng chịu nhiều cuộc tấn công mạng cả về số lượng cũng như kỹ thuật tấn công, đặc biệt là kỹ thuật tấn công từ chối dịch vụ - DDoS. Bởi chính ý tưởng tách rời phần điều khiển ra khỏi phần chuyển tiếp dữ liệu để tập trung hóa việc điều khiển hệ thống mạng tại Controller đã vô tình biến nó thành điểm mỏi trong hệ thống và là mục tiêu chính của những kẻ tấn công. Khi controller của hệ thống mạng sụp đổ, toàn bộ hoạt động của mạng sẽ bị tê liệt.
Vì vậy, việc bảo vệ controller trong kiến trúc SDN là nhiệm vụ quan trọng và cấp thiết. Để bảo vệ cho controller, ngoài phương án tăng cường sức mạnh cho chính nó, ý tưởng chống tấn công từ phần chuyển tiếp dữ liệu cũng đáng được xem xét vì nó tỏ ra hữu hiệu khi giúp hệ thống mạng có khả năng phòng vệ sớm trước khi gói tin tấn công đến được controller, từ đó giảm thiểu rủi ro sụp đổ cả hệ thống do controller bị phá hoại. Xuất phát từ ý tưởng này, chúng tôi đề xuất kiến trúc bảo mật cho thiết bị chuyển mạch của OpenFlow network - là một hiện hữu phổ biến và thành công nhất trong hướng tiếp cận SDN. Đây là kiến trúc kết hợp giữa chức năng xử lý OpenFlow để chuyển tiếp gói tin theo giao thức OpenFlow với chức năng xử lý bảo mật để chống lại các hình thức tấn công mạng.
Cụ thể hơn, công trình nghiên cứu của luận văn thạc sĩ này bắt đầu từ việc đưa A BSTRACT v ra kiến trúc và xây dựng một loại thiết bị chuyển mạch OpenFlow có tích hợp thêm chức năng bảo mật ở mức phần cứng để thử nghiệm và đánh giá tính khả thi của ý tưởng. Từ cơ sở đó, công trình hướng tới việc nghiên cứu và xây dựng framework để cung cấp tiện ích phục vụ nghiên cứu những vấn đề bảo mật cho hệ thống mạng OpenFlow theo hướng chống lại các hình thức công mạng từ lớp data plane.