首页> 外文会议>IEEE International Symposium on Network Computing and Applications >Gwardar: Towards Protecting a Software-Defined Network from Malicious Network Operating Systems
【24h】

Gwardar: Towards Protecting a Software-Defined Network from Malicious Network Operating Systems

机译:GCANDAR:朝来保护软件定义网络免受恶意网络操作系统

获取原文

摘要

A Software-Defined Network (SDN) controller (aka. Network Operating System or NOS) is regarded as the brain of the network and is the single most critical element responsible to manage an SDN. Complimentary to existing solutions that aim to protect a NOS, we propose an intrusion protection system designed to protect an SDN against a controller that has been successfully compromised. Gwardar maintains a virtual replica of the data plane by intercepting the OpenFlow messages exchanged between the control and data plane. By observing the long-term flow of the packets, Gwardar learns the normal set of trajectories in the data plane for distinct packet headers. Upon detecting an unexpected packet trajectory, it starts by verifying the data plane forwarding devices by comparing the actual packet trajectories with the expected ones computed over the virtual replica. If the anomalous trajectories match the NOS instructions, Gwardar inspects the NOS itself. For this, it submits policies matching the normal set of trajectories and verifies whether the controller submits matching flow rules to the data plane and whether the network view provided to the application plane reflects the changes. Our evaluation results prove the practicality of Gwardar with a high detection accuracy in a reasonable time-frame.
机译:一个软件定义的网络(SDN)控制器(AKA。网络操作系统或NOS)被视为网络的大脑,是负责管理SDN的单个最关键的元素。旨在保护NOS的现有解决方案,我们提出了一种入侵保护系统,旨在保护SDN对已成功损害的控制器。 G调花通过拦截在控制和数据平面之间交换的OpenFlow消息来维护数据平面的虚拟副本。通过观察数据包的长期流量,G调花将在数据平面中学习正常的轨迹,用于不同的分组标题。在检测到意外的分组轨迹时,它通过将数据平面转发设备进行验证,通过将实际的分组轨迹与在虚拟副本上计算的预期数据包轨迹进行比较来开始。如果异常轨迹与NOS指示相匹配,则G调座检查了NOS本身。为此,它提出了匹配正常轨迹集的策略,并验证控制器是否向数据平面提交匹配的流规则以及提供给应用程序平面的网络视图是否反映了更改。我们的评估结果在合理的时间框架中证明了Gadarar的实用性具有高检测精度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号