【24h】

FloodShield: Securing the SDN Infrastructure Against Denial-of-Service Attacks

机译:FloodShield:保护SDN基础架构免受拒绝服务攻击

获取原文
获取原文并翻译 | 示例

摘要

Software-Defined Networking (SDN) has attracted great attention from both academia and industry. However, the deployment of SDN has faced some critical security issues, such as Denial-of-Service (DoS) attacks on the SDN infrastructure. One such DoS attack is the data-to-control plane saturation attack, where an attacker floods a large number of packets to trigger massive table-misses and packet-in messages in the data plane. This attack can exhaust resources of different components of the SDN infrastructure, including TCAM and buffer memory in the data plane, bandwidth of the control channel, and CPU cycles of the controller. In this paper, we analyze the vulnerability of SDN against the data-to-control plane saturation attack extensively and design FloodShield, a comprehensive, deployable and lightweight SDN defense framework to mitigate this dedicated DoS attack. FloodShield combines the following two techniques: 1) source address validation which filters forged packets directly in the data plane, and 2) stateful packet supervision which monitors traffic states of real addresses and performs dynamic countermeasures based on evaluation scores and network resource usages. Implementations and experiments demonstrate that, compared with previous defense frameworks, FloodShield provides effective protection for all three components of the SDN infrastructure - data plane, control channel and control plane - with less resource consumption.
机译:软件定义网络(SDN)引起了学术界和行业的极大关注。但是,SDN部署面临一些关键的安全问题,例如对SDN基础结构的拒绝服务(DoS)攻击。一种这样的DoS攻击是数据到控制平面的饱和攻击,攻击者在其中攻击大量数据包,从而触发数据平面中的大量表丢失和数据包进入消息。这种攻击可能耗尽SDN基础架构不同组件的资源,包括数据平面中的TCAM和缓冲存储器,控制通道的带宽以及控制器的CPU周期。在本文中,我们广泛分析了SDN对数据到控制平面饱和攻击的脆弱性,并设计了FloodShield,FloodShield是一种全面,可部署且轻量级的SDN防御框架,可以缓解这种专用的DoS攻击。 FloodShield结合了以下两种技术:1)源地址验证,可直接在数据平面中过滤伪造的数据包,以及2)有状态的数据包监管,可监视真实地址的流量状态并根据评估分数和网络资源使用情况执行动态对策。实施和实验表明,与以前的防御框架相比,FloodShield为SDN基础结构的所有三个组件(数据平面,控制通道和控制平面)提供了有效的保护,而资源消耗却更少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号