首页> 外文会议>International Conference on Signal Processing and Integrated Networks >FlowTrApp: An SDN based architecture for DDoS attack detection and mitigation in data centers
【24h】

FlowTrApp: An SDN based architecture for DDoS attack detection and mitigation in data centers

机译:FlowTrApp:基于SDN的体系结构,用于数据中心中的DDoS攻击检测和缓解

获取原文

摘要

Distributed Denial of Service attack (DDoS) is one of the severe security problems in data centers. In present times, data center operators adopt several hardware based dedicated measures for detection and mitigation of such attacks. It is a challenging task always to detect and mitigate DDoS attacks completely. Software Defined Network (SDN) provides a central control over the network which helps in getting the global view of the network. In this paper, we propose an SDN framework for data centers named FlowTrApp which performs DDoS detection and mitigation using some bounds on two per flow based traffic parameters i.e., flow rate and flow duration of a flow. It attempts to detect attack traffic ranging from low rate to high rate and long lived to short lived attacks using an SDN engine consisting of sFlow based flow analytics engine sFlow-RT and an OpenFlow controller. The proposed framework of FlowTrApp has been implemented in mininet emulator which outperforms an OpenFlow based QoS approach for DoS attack mitigation.
机译:分布式拒绝服务攻击(DDoS)是数据中心中严重的安全问题之一。当前,数据中心运营商采用了几种基于硬件的专用措施来检测和缓解此类攻击。始终完全检测和缓解DDoS攻击始终是一项艰巨的任务。软件定义网络(SDN)提供了对网络的集中控制,有助于获得网络的全局视图。在本文中,我们为数据中心提出了一个名为FlowTrApp的SDN框架,该框架使用基于每个流量的两个流量参数(即流量和流量持续时间)的两个界限执行DDoS检测和缓解。它尝试使用由基于sFlow的流分析引擎sFlow-RT和OpenFlow控制器组成的SDN引擎检测从低速率到高速率以及长寿命到短寿命攻击的攻击流量。所提出的FlowTrApp框架已在小型网络仿真器中实现,该仿真器性能优于基于OpenFlow的QoS缓解DoS攻击的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号