首页> 外文会议>International Conference on Signal Processing and Integrated Networks >FlowTrApp: An SDN based architecture for DDoS attack detection and mitigation in data centers
【24h】

FlowTrApp: An SDN based architecture for DDoS attack detection and mitigation in data centers

机译:Flowtrapp:基于SDN的DDOS攻击检测和数据中心缓解的架构

获取原文
获取外文期刊封面目录资料

摘要

Distributed Denial of Service attack (DDoS) is one of the severe security problems in data centers. In present times, data center operators adopt several hardware based dedicated measures for detection and mitigation of such attacks. It is a challenging task always to detect and mitigate DDoS attacks completely. Software Defined Network (SDN) provides a central control over the network which helps in getting the global view of the network. In this paper, we propose an SDN framework for data centers named FlowTrApp which performs DDoS detection and mitigation using some bounds on two per flow based traffic parameters i.e., flow rate and flow duration of a flow. It attempts to detect attack traffic ranging from low rate to high rate and long lived to short lived attacks using an SDN engine consisting of sFlow based flow analytics engine sFlow-RT and an OpenFlow controller. The proposed framework of FlowTrApp has been implemented in mininet emulator which outperforms an OpenFlow based QoS approach for DoS attack mitigation.
机译:分布式拒绝服务攻击(DDOS)是数据中心的严重安全问题之一。在现在的时间内,数据中心运营商采用了几种基于硬件的专用措施,以检测和减轻此类攻击。这是一个具有挑战性的任务,始终完全检测和减轻DDOS攻击。软件定义的网络(SDN)提供了通过网络的中央控制,有助于获取网络的全局视图。在本文中,我们提出了一个名为FlowTrapp的数据中心的SDN框架,其使用基于每个流量的交通参数的两个界限执行DDOS检测和缓解,流量和流量的流量持续时间。它试图检测从低速率到高速度的攻击流量,并且使用由SDF的流分析发动机SFLOW-RT和OpenFlow控制器组成的SDN发动机来检测高速率的攻击流量。拟议的FlowTrapp框架已经在MinInet仿真器中实现,这胜过了基于OpenFlow的QoS方法,用于DOS攻击缓解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号