首页> 外文会议>IEEE Military Communications Conference >An SDN-supported collaborative approach for DDoS flooding detection and containment
【24h】

An SDN-supported collaborative approach for DDoS flooding detection and containment

机译:支持DDOS泛洪检测和遏制的SDN支持的协作方法

获取原文

摘要

Software Defined Networking (SDN) has the potential to enable novel security applications that support flexible, on-demand deployment of system elements. It can offer targeted forensic evidence collection and investigation of computer network attacks. Such unique capabilities are instrumental to network intrusion detection that is challenged by large volumes of data and complex network topologies. This paper presents an innovative approach that coordinates distributed network traffic Monitors and attack Correlators supported by Open Virtual Switches (OVS). The Monitors conduct anomaly detection and the Correlators perform deep packet inspection for attack signature recognition. These elements take advantage of complementary views and information availability on both the data and control planes. Moreover, they collaboratively look for network flooding attack signature constituents that possess different characteristics in the level of information abstraction. Therefore, this approach is able to not only quickly raise an alert against potential threats, but also follow it up with careful verification to reduce false alarms. We experiment with this SDN-supported collaborative approach to detect TCP SYN flood attacks on the Global Environment for Network Innovations (GENI), a realistic virtual testbed. The response times and detection accuracy, in the context of a small to medium corporate network, have demonstrated its effectiveness and scalability.
机译:软件定义的网络(SDN)有可能启用新的安全应用程序,这些应用程序支持灵活,按需部署的系统元素。它可以提供有针对性的法医证据收集和计算机网络攻击调查。这种独特的能力是由大量数据和复杂网络拓扑挑战的网络入侵检测。本文介绍了一种创新方法,可协调分布式网络流量监视器和开放虚拟交换机(OVS)支持的攻击相关器。监视器进行异常检测,并且相关器对攻击签名识别进行深度分组检查。这些元素利用数据和控制平面上的互补视图和信息可用性。此外,他们协同寻找网络泛滥攻击签名成分,其具有信息抽象级别的不同特征。因此,这种方法能够不仅能够快速提高警报,而且还要仔细验证,以减少误报。我们试验此SDN支持的协作方法,以检测关于网络创新的全球环境(Geni)的TCP SYN泛滥攻击,这是一个现实的虚拟测试。在小于中型公司网络的上下文中,响应时间和检测准确性证明了其有效性和可扩展性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号