首页> 外文会议>IEEE International Performance Computing and Communications Conference >Network intrusion detection and prevention middlebox management in SDN
【24h】

Network intrusion detection and prevention middlebox management in SDN

机译:SDN中的网络入侵检测与预防中间箱管理

获取原文

摘要

In traditional networks, it is difficult to manage the distributed detection and prevention nodes of IDS and IPS due to the laborious manual deployment and independent configuration. Software defined networking (SDN) provides a flexible approach to control the underlying network infrastructures efficiently. However, the OpenFlow flow table is too simple to provide complex functions with the match-action style processing. To support more functionalities, in this paper, we propose a middlebox management architecture with SDN - OpenMiddlebox, by extending OpenFlow to support middleboxes with ClickOS virtual machines (VM), so that programmable middleboxes could be deployed and managed in switches with fast booted ClickOS VMs flexibly. We then design automatic deployment and update schemes of network intrusion detection and prevention middleboxes with the centralized controller. The evaluation results show that OpenMiddlebox could manage the distributed middleboxes efficiently and is scalable to large networks, and the centralized control also improves the network intrusion detection and prevention accuracy.
机译:在传统网络中,由于费力的手动部署和独立配置,难以管理ID和IP的分布式检测和预防节点。软件定义的网络(SDN)提供了一种灵活的方法,可以有效地控制底层网络基础架构。但是,OpenFlow流表太简单,无法提供匹配动作样式处理的复杂功能。为了支持更多功能,请在本文中,通过扩展OpenFlow来支持具有ClickoS虚拟机(VM)的中间盒来支持SDN - OpenMiddlebox的中间箱管理架构,以便在具有快速启动ClickoS VM的交换机中部署和管理可编程中间盒灵活地。然后,我们使用集中控制器设计自动部署和更新网络入侵检测和预防中间盒的方案。评估结果表明,OpenMiddlebox可以有效地管理分布式的中间盒,并且可以扩展到大型网络,集中控制还提高了网络入侵检测和预防准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号