首页> 外文会议>2017 IEEE Conference on Network Function Virtualization and Software Defined Networks >A low-delay SDN-based countermeasure to eavesdropping attacks in industrial control systems
【24h】

A low-delay SDN-based countermeasure to eavesdropping attacks in industrial control systems

机译:一种基于SDN的低延迟对策,用于窃听工业控制系统中的攻击

获取原文
获取原文并翻译 | 示例

摘要

Industrial Control Systems (ICS) and their networking infrastructure have been the target of an increasing number of cyber-attacks over the past years. In 2015, researchers proposed to employ SDN techniques to improve the security of ICS networks. To avoid that all packets are forwarded along the same path in such a network, their multipath routing strategy alternates between several paths from a source host to the destination host, such that an eavesdropper cannot capture the entire communication. We show that a basic multipath routing strategy can lead to delay peaks in the ICS network which are, considering the real-time nature of the network traffic in an ICS, highly undesired. We propose the priority multipath routing strategy which avoids such delays. Our approach makes use of rule priorities in OpenFlow to ensure that there is always a matching forwarding rule in a switch. We also propose to consider the path selection process as solving a convex flow problem. We validate our approach by simulation experiments. Our results show that our approach significantly reduces the number of table misses and effectively eliminates delay peaks and that selected paths compromise well between their disjointness and their cost.
机译:在过去的几年中,工业控制系统(ICS)及其网络基础设施已成为越来越多的网络攻击的目标。在2015年,研究人员提议采用SDN技术来提高ICS网络的安全性。为了避免所有数据包都沿着这样的网络中的同一路径转发,它们的多路径路由策略会在从源主机到目标主机的多个路径之间交替切换,以使窃听者无法捕获整个通信。我们表明,基本的多路径路由策略会导致ICS网络中的延迟峰值,考虑到ICS中网络流量的实时性,这是非常不希望的。我们提出了避免这种延迟的优先级多路径路由策略。我们的方法利用OpenFlow中的规则优先级来确保交换机中始终存在匹配的转发规则。我们还建议将路径选择过程视为解决凸流问题。我们通过仿真实验验证了我们的方法。我们的结果表明,我们的方法显着减少了表丢失的次数,并有效地消除了延迟峰值,并且所选路径很好地折衷了它们的不连贯性和成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号