| |
Jonghoon Kwon, Taeho Lee, Claude Hähni, Adrian Perrig ETH Zürich, Network Security Group
25.02.2020 1
SVLAN: Secure & Scalable Network Virtualization
Jonghoon Kwon, Ph.D
SVLAN: Secure & Scalable Network Virtualization Jonghoon Kwon, - - PowerPoint PPT Presentation
SVLAN: Secure & Scalable Network Virtualization Jonghoon Kwon, Taeho Lee, Claude Hhni, Adrian Perrig ETH Zrich, Network Security Group Jonghoon Kwon, Ph.D | | 25.02.2020 1 Current Inter-domain Network Virtualization: VLAN PM PM PM
| |
Jonghoon Kwon, Taeho Lee, Claude Hähni, Adrian Perrig ETH Zürich, Network Security Group
25.02.2020 1
Jonghoon Kwon, Ph.D
| | 25.02.2020 Jonghoon Kwon, Ph.D 2
PM PM
Layer-2 bridging Supporting apx. 4 K virtual networks with a 12-bit VID value
PM PM
Internet
ETH | VLAN | IP | Data VID 101 VID 102
| | 25.02.2020 Jonghoon Kwon, Ph.D 3
VM VM Hypervisor
Internet
Edge Network
Supporting 16 M virtual networks with a 24-bit VNI value Interconnecting layer-2 networks over an underlying layer-3 network
VTEP VM VM Hypervisor Core Network VTEP
ETH | IP | Data VXLAN tunnel Outer ETH | Outer IP | Outer UDP | VXLAN | ETH | IP | Data ETH | IP | Data VNI 1001 VNI 1002
| | 25.02.2020 Jonghoon Kwon, Ph.D 4
Compromise Network Isolation Disrupt Virtual Network Security Scalability Flexibility
| | 25.02.2020 Jonghoon Kwon, Ph.D 5
VM VM Hypervisor
Internet
VTEP VM VM Hypervisor VTEP
Trusted Trusted Untrusted
Outer ETH | Outer IP | Outer UDP | VXLAN | ETH | IP | Data
Attackers may manipulate VNIs and forward malicious traffic
Edge Network Core Network
| | 25.02.2020 Jonghoon Kwon, Ph.D 6
VM VM Hypervisor VTEP VM VM Hypervisor VTEP VM VM VM VM VM VM VM
Internet
Edge Network Core Network
| | 25.02.2020 Jonghoon Kwon, Ph.D 7
VM VM Hypervisor VTEP VM VM Hypervisor VTEP
Internet
Edge Network Core Network
| | 25.02.2020 Jonghoon Kwon, Ph.D 8
VM VM Hypervisor VTEP VM VM Hypervisor VTEP
Internet
Edge Network Core Network
| | 25.02.2020 Jonghoon Kwon, Ph.D 9
Intra-domain network slicing (Destination-driven connectivity)
Verifiable Inter-domain routing (Packet-carrying forwarding state)
| | 25.02.2020 10
Jonghoon Kwon, Ph.D
Untrusted Network Untrusted Network
Edge network Core network
Mobile Slice IoT Slice Mission critical Slice
| | 25.02.2020 11
Jonghoon Kwon, Ph.D
VM VM Hypervisor SVTEP
Receiver
VM VM Hypervisor SVTEP
Sender Authorization Delegate
SVLAN tunnel
Verifier
| | 25.02.2020 12
Jonghoon Kwon, Ph.D
VM VM Hypervisor SVTEP VM VM Hypervisor SVTEP
Receiver Sender
| | 25.02.2020 13
Jonghoon Kwon, Ph.D
VM VM Hypervisor SVTEP VM VM Hypervisor SVTEP
Receiver Sender
| | 25.02.2020 14
Jonghoon Kwon, Ph.D
VM VM Hypervisor SVTEP VM VM Hypervisor SVTEP
Receiver Sender
| | 25.02.2020 15
Jonghoon Kwon, Ph.D
VM VM Hypervisor SVTEP VM VM Hypervisor SVTEP
Receiver Sender
| | 25.02.2020 16
Jonghoon Kwon, Ph.D
VM VM Hypervisor SVTEP VM VM Hypervisor SVTEP
Receiver Sender
| | 25.02.2020 Jonghoon Kwon, Ph.D 17
https://github.com/scionproto/scion https://www.scionlab.org
| | 25.02.2020 Jonghoon Kwon, Ph.D 18
| | 25.02.2020 Jonghoon Kwon, Ph.D 19
§ 36 bytes of additional header
§ 12 bytes of MPLS labels (three labels) § 24 bytes of proof
§ 60 bytes of additional header
§ 24 bytes of forwarding paths (three labels) § 32 bytes of extra header
| | 25.02.2020 Jonghoon Kwon, Ph.D 20
| | 25.02.2020 Jonghoon Kwon, Ph.D 21
Authorization Delegate Sender Receiver
| | 25.02.2020 Jonghoon Kwon, Ph.D 22
| | 25.02.2020 Jonghoon Kwon, Ph.D 23
| | 25.02.2020 Jonghoon Kwon, Ph.D 24
§ Unlimited number of VNI § Stateless VTEP
§ Only authorized packets get forwarded § Adversaries cannot impersonate authorized senders
§ Receiving policy at different granularity § Easy update for virtual network
§ No ARP flooding § Negligible latency influence
Jonghoon Kwon, Taeho Lee, Claude Hähni, Adrian Perrig (jong.kwon@inf.ethz.ch) ETH Zurich Network Security Group Universitätstrasse 6 8092 Zürich https://netsec.ethz.ch
| | 1.12.2014 First name Surname (edit via “Insert” > “Header & Footer”) 26
| | 25.02.2020 27
Jonghoon Kwon, Ph.D
| | 25.02.2020 28
Jonghoon Kwon, Ph.D
VM VM SVTEP
Sender
Hypervisor VM VM Hypervisor SVTEP
Receiver
| | 25.02.2020 29
Jonghoon Kwon, Ph.D
VM VM SVTEP
Sender
Hypervisor VM VM Hypervisor SVTEP
Receiver