The Finest Penetration Testing Framework for Software Defined Networks @HackersOnBoard
The Finest Penetration Testing Framework for Software Defined Networks  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 3 days ago
Black Hat USA 2018
Software-Defined Networking (SDN) is getting attention for the next-generation networking today. The key concept of SDN is to decouple the control logic from the traditional network devices so that network developers can design innovative network functions in a more flexible and programmable way. However, SDN is not always bringing advantages to us. Security experts have constantly raised security concerns about SDN, and some vulnerabilities have been uncovered in the real world. If SDN is not secure, how can we measure the security level of SDN environments?

In this talk, we introduce a powerful penetration testing tool for SDN called DELTA, which is officially supported by Open Networking Foundation (ONF). First, DELTA can automate diverse published attack scenarios against various SDN components from testing to evaluating. Also, to discover unknown vulnerabilities that may exist in SDN, DELTA leverages a blackbox fuzzing technique that randomizes different control flows in SDN. It enables us to systemically reveal unknown security issues rather than the empirical and ad-hoc methods that most previous studies use. By using DELTA, anyone can easily and thoroughly test not only popular open source SDN controllers (i.e., ONOS, OpenDaylight, Floodlight, and Ryu), but also SDN-enabled switches (i.e., OpenvSwitch, HP, and Pica8) in the real world.

We will show nine new attack cases that have been found by DELTA but never been announced before.

Also, we will discuss:
- What control flows are in SDN, and why those are important as a key feature compared to the traditional networks.
- What key components and workflow of DELTA to attack the real SDN components.
- Which nine new attack cases have been discovered by DELTA, and we will demonstrate it. For example, one of the new attacks violates the table condition, leading to the black hole of handling packets in the switch.
The Finest Penetration Testing Framework for Software Defined NetworksDEF CON 27 - Christopher Wade - Tag-side attacks against NFCDEF CON 27 - Joseph Menn - Change the World cDc Style Cow tips from the first 35 yearsBehind the Speculative Curtain The True Story of Fighting Meltdown and SpectreBlack Hat USA 2018 - Lowering the Bar Deep Learning for Side Channel AnalysisBlack Hat USA 2018 - Identity Theft Attacks on SSO SystemsSubverting Sysmon: Application of a Formalized Security Product Evasion MethodologyBlack Hat USA 2018 - WebAssembly A New World of Native Exploits on the BrowserBlack Hat USA 2018 - Dont @ Me Hunting Twitter Bots at ScaleBlack Hat USA 2018 - Demystifying PTSD in the Cybersecurity EnvironmentDEF CON 27 - Bug Finding And Exploit Techniques On File Transfer App Of All Top Android VendorsBlack Hat USA 2018 - Attacking Client Side JIT Compilers
HackersOnBoard |

The Finest Penetration Testing Framework for Software Defined Networks

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER