DEF CON 26 - Xiao and Panel - Hacking the Brain Customize Evil Protocol to Pwn an SDN Con
1,115 views · Published 22 October 2018 · 18:32 · Indexed 26 September 2026
Channel: DEFCONConference · 2018 · Science & Technology
Software-Defined Networking (SDN) is now widely deployed in production environments with an ever-growing community. Though SDN's software-based architecture enables network programmability, it also introduces dangerous code vulnerabilities into SDN controllers. However, the decoupled SDN control plane and data plane only communicate with each other with pre-defined protocol interactions, which largely increases the difficulty of exploiting such security weaknesses from the data plane. In this talk, we extend the attack surface and introduce Custom Attack, a novel attack against SDN controllers that leverages legitimate SDN protocol messages (i.e., the custom protocol field) to facilitate Java code vulnerability exploitation. Our research shows that it was possible for a weak adversary to execute arbitrary command or manipulate data in the SDN controller without accessing the SDN controller or any applications, but only controlling a host or a switch. To the best of our knowledge, Custom Attack is the first attack that can remotely compromise SDN software stack to simultaneously cause multiple kinds of attack effects in SDN controllers. Till now we have tested 5 most popular SDN controllers and their applications and found all of them are vulnerable to Custom Attack in some degree. 14 serious vulnerabilities are discovered, all of which can be exploited remotely to launch advanced attacks against controllers (e.g., executing arbitrary commands, exfiltrating confidential files, crashing SDN service, etc.). This presentation will include: an overview of SDN security research and practices. a new attack methodology for SDN that is capable of compromising the entire network. our research process that leads to these discoveries, including technical specifics of exploits. showcases of interesting Custom Attack chains in real-world SDN projects.
More from this channel
-
7:53
DEF CON 20 Documentary Bonus Clips - CDC muxed
-
25:01
DEF CON 20 - Ryan Holeman - Passive Bluetooth Monitoring in Scapy
-
48:14
DEF CON 20 - Xeno Kovah and Corey Kallenberg - No More Hooks
-
51:04
DEF CON 20 - Panel - The Making of DEF CON 20
-
50:01
DEF CON 20 - Josh "m0nk" Thomas and Jeff "stoker" Robble - Off-Grid Communications with Android
-
50:01
DEF CON 20 - Jason Ostrom, Karl Feinauer, William Borskey - The End of the PSTN As You Know It
-
50:11
DEF CON 20 - Michael Robinson and Chris Taylor - Spy vs Spy: Spying on Mobile Device Spyware
-
36:49
DEF CON 19 - Engebretson & Pauli - Mamma Dont Let Your BabiesGrow Up to be Pen Testers