期刊文献+

一种针对基于OpenFlow的SDN网络中控制层面的DoS攻击研究 被引量:6

Research on DoS Attacks Against Control Level in OpenFlow-based SDN
下载PDF
导出
摘要 针对OpenFlow协议报文交换机制里所有非数据报文均需要通过PACKET_IN报文上传控制器的弱点,提出一种不停查询未知转发地址从而造成SDN网络控制层面资源耗尽的新型DoS攻击方式,同时基于SDN网络可编程性提出检测攻击与降低网络时延的解决策略。首先通过SDN控制器北向应用接口,使用Defense4ALL应用中自定义功能,针对DoS攻击特性检测网络中恶意流量。然后利用控制器动态配置特性,实时更新交换机配置文件,改变网络转发策略,从而减轻攻击对整个网络造成的影响。实验仿真表明,在大规模高速攻击中,该方法的检测成功率接近100%,在攻击源较少的慢速攻击中检测成功率低于80%,整体网络延迟降低10ms以上。所提出的解决策略可以有效减少针对控制平面的DoS攻击对整个网络的干扰。 Based on OpenFlow protocol message exchange mechanism, all non-data packets need uploading by PACKET_IN message. Thus, a new DoS attack on the control plane was proposed. It uses non-stop forwarding unknown address packages to deplete resources in control plane. And a solution strategy was proposed to detect attacks and reduce network latency based on the programmability of SDN network. First, through SDN controller north application interface, Defense4ALL application was used to detect malicious traffic by characteristic of DoS attacks. Then by using the controller feature of dynamical configuration, switch configuration file was updated in real-time, and network forwarding policy was changed. Thereby it could reduce the damage caused by the attack on the entire network. The simulation shows that the success rate of this detection method closes to 100 %. But in slow-speed less-source attack detection success rate is less than 80%. The overall network latency is reduced by 10ms or more. The proposed solution strategy can effectively reduce the interference of the DoS attacks against control level for entire network.
作者 楼恒越 窦军
出处 《计算机科学》 CSCD 北大核心 2015年第B11期341-344,共4页 Computer Science
关键词 SDN OpenFlow 网络安全 控制层面 DOS攻击 SDN, OpenFlow, Network security, Control level, DoS attack
  • 相关文献

参考文献17

二级参考文献175

  • 1林闯,任丰原.可控可信可扩展的新一代互联网[J].软件学报,2004,15(12):1815-1821. 被引量:79
  • 2林闯,彭雪海.可信网络研究[J].计算机学报,2005,28(5):751-758. 被引量:253
  • 3林闯,汪洋,李泉林.网络安全的随机模型方法与评价技术[J].计算机学报,2005,28(12):1943-1956. 被引量:92
  • 4郭阳勇,窦军,李云婷.SUPANET的专用连接释放协议[J].通讯和计算机(中英文版),2005,2(2):76-81. 被引量:1
  • 5林闯,雷蕾.下一代互联网体系结构研究[J].计算机学报,2007,30(5):693-711. 被引量:64
  • 6FUTURE INTERNET ASSEMBLY 2009pOL]. Stockholm, Sweden, November 2009 : 23-24.
  • 7Dou Jun, Xia Yu, Chen Xi. Future Network Applications, Network Model, and Development Strategy [C] // Proceedings of FADS'2009(International Workshop on Future network Architecture and Development Strategy). Madrid, Spain, September 2009.
  • 8Zeng Hua-xin, Dou Jun, Xu Deng-yuan. Single physical layer Uplane Architecture(SUPA) for Next Generation Internet[R]. Comprehensive Report on VolP and enhanced IP Communications Services. IEC Publications, 2004 : 197-227.
  • 9Zeng Hua-xin,Gao Yu, Xia Yu. On NGN architecture and evolution strateg[C]//Proeeedings of the first ITU-T Kaleidoscope Academic Conference, Innovations in NGN: Future Network and Services. Geneva, May 2008 : 337-342.
  • 10Zeng Humxin, Dou Jun, Xu Deng-yuan. Replace MPLS with EPFTS to build a SUPANET[C]//Proceedings of 2005 IEEE International Workshop on High Performance Switching and Routing( HPSR' 05). Hong Kong, May 2005 : 39-43.

共引文献618

同被引文献39

引证文献6

二级引证文献20

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部