首页> 外文会议>IEEE International Performance Computing and Communications Conference >Network intrusion detection and prevention middlebox management in SDN
【24h】

Network intrusion detection and prevention middlebox management in SDN

机译:SDN中的网络入侵检测和预防中间盒管理

获取原文

摘要

In traditional networks, it is difficult to manage the distributed detection and prevention nodes of IDS and IPS due to the laborious manual deployment and independent configuration. Software defined networking (SDN) provides a flexible approach to control the underlying network infrastructures efficiently. However, the OpenFlow flow table is too simple to provide complex functions with the match-action style processing. To support more functionalities, in this paper, we propose a middlebox management architecture with SDN - OpenMiddlebox, by extending OpenFlow to support middleboxes with ClickOS virtual machines (VM), so that programmable middleboxes could be deployed and managed in switches with fast booted ClickOS VMs flexibly. We then design automatic deployment and update schemes of network intrusion detection and prevention middleboxes with the centralized controller. The evaluation results show that OpenMiddlebox could manage the distributed middleboxes efficiently and is scalable to large networks, and the centralized control also improves the network intrusion detection and prevention accuracy.
机译:在传统网络中,由于费力的手动部署和独立配置,因此难以管理IDS和IPS的分布式检测和防御节点。软件定义网络(SDN)提供了一种灵活的方法来有效地控制基础网络基础结构。但是,OpenFlow流表太简单了,无法通过匹配动作样式处理提供复杂的功能。为了支持更多功能,在本文中,我们通过扩展OpenFlow以支持具有ClickOS虚拟机(VM)的中间盒,提出了一种带有SDN的中间盒管理体系结构-OpenMiddlebox,以便可以在具有快速启动的ClickOS VM的交换机中部署和管理可编程中间盒。灵活地。然后,我们使用集中控制器设计网络入侵检测和预防中间盒的自动部署和更新方案。评估结果表明,OpenMiddlebox可以有效地管理分布式中间箱,并且可以扩展到大型网络,并且集中控制还可以提高网络入侵检测和预防的准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号