【24h】

SDN-Guard: Protecting SDN controllers against SDN rootkits

机译:SDN-Guard:保护SDN控制器免受SDN Rootkit的攻击

获取原文
获取原文并翻译 | 示例

摘要

Software-defined networking (SDN) addresses pressing networking problems such as network virtualization and data center complexity. By separating the control plane from the data plane, SDN introduces a new abstraction layer. This new abstraction layer is typically implemented by means of a so-called SDN controller. SDN applications can interact with the controller to ensure network functionality. This new paradigm has multiple advantages, particularly in the fields of network automation and security. Recent work, however, has shown that existing SDN solutions lack adequate security properties; in particular, SDN rootkits allow attackers to take over entire networks by compromising SDN controllers. In this paper, we present SDN-Guard, a novel system for detecting and mitigating SDN rootkits. The basic idea is to perform a dual-view comparison that detects malicious network programming attempts. An evaluation of our system demonstrates both its effectiveness and its flexibility in terms of application, along with its relatively small performance overhead.
机译:软件定义网络(SDN)解决了紧迫的网络问题,例如网络虚拟化和数据中心复杂性。通过将控制平面与数据平面分离,SDN引入了新的抽象层。这种新的抽象层通常是通过所谓的SDN控制器实现的。 SDN应用程序可以与控制器交互以确保网络功能。这种新范例具有多重优势,尤其是在网络自动化和安全领域。但是,最近的工作表明,现有的SDN解决方案缺乏足够的安全性。特别是,SDN rootkit允许攻击者通过破坏SDN控制器来接管整个网络。在本文中,我们介绍了SDN-Guard,这是一种用于检测和缓解SDN Rootkit的新颖系统。基本思想是执行双重视图比较,以检测恶意网络编程尝试。对我们的系统进行的评估证明了其有效性和灵活性,以及​​相对较小的性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号