【24h】

Detection as a service: An SDN application

机译:检测即服务:SDN应用程序

获取原文

摘要

In a cloud computing environment, future networks will most probably utilize network functions virtualization (NFV) which is a network architecture concept that proposes virtualizing network node functions into “building blocks” or entities that may be operationally connected or linked together to provide services. However, applying these mechanisms brings security challenges. Due to the programmability of software defined networking (SDN), if attackers gain access to an SDN controller, then the whole network may be exploited by the attackers. The attackers may change forwarding paths and pass malicious traffic to infect the SDN enabled network. To detect the security attacks and malicious traffic early enough and to protect the network, centralized monitoring and intrusion detection system (IDS) monitoring may be used for enhancing SDN, NFV and OpenFlow security. If the network traffic is analysed and the anomalies are detected, the SDN controller may be used to block such traffic from passing through the network by flow control, i.e. forwarding paths in a switch. IDS and intrusion prevention system (IPS) may be deployed at the gateway node to detect a security intrusion. Thus, the data traffic originated from a subscriber passes through each network element until the traffic reaches the gateway node. Such traffic may attack the network elements and may also cause a denial of service (DoS) attack in the network. IDS devices are designed to handle network traffic in real time, yet the cost and high processing time is a challenge for handling the traffic load. Combining dynamicity and programmability of SDN together with traffic filtering of IDS, enables a scalable, redundant and reliable anomaly detection for mobile network operators. In this study, we propose an architecture that combines IDS with programmability features of SDN for detection and mitigation of malicious traffic. Mitigation will be performed by SDN controller using flow control techniques. The proposed architecture can be applied to an SDN enabled mobile network with two different approaches for improved performance in terms of computation power.
机译:在云计算环境中,未来的网络将最有可能利用网络功能虚拟化(NFV),这是一种网络架构概念,提出将网络节点功能虚拟化为可在操作上连接或链接在一起以提供服务的“构建块”或实体。但是,应用这些机制带来了安全挑战。由于软件定义网络(SDN)的可编程性,如果攻击者获得对SDN控制器的访问权限,则整个网络可能会被攻击者利用。攻击者可能会更改转发路径并传递恶意流量,以感染启用SDN的网络。为了尽早检测安全攻击和恶意流量并保护网络,可以使用集中式监视和入侵检测系统(IDS)监视来增强SDN,NFV和OpenFlow的安全性。如果分析了网络流量并检测到异常,则可以使用SDN控制器通过流控制(即在交换机中转发路径)阻止此类流量通过网络。 IDS和入侵防御系统(IPS)可以部署在网关节点上,以检测安全入侵。因此,源自订户的数据业务通过每个网元,直到业务到达网关节点。这样的流量可能会攻击网络元素,也可能导致网络中的拒绝服务(DoS)攻击。 IDS设备旨在实时处理网络流量,但是成本和高处理时间是处理流量负载的挑战。 SDN的动态性和可编程性与IDS的流量过滤相结合,为移动网络运营商提供了可扩展,冗余且可靠的异常检测。在这项研究中,我们提出了一种将IDS与SDN的可编程功能相结合的体系结构,用于检测和缓解恶意流量。缓解将由SDN控制器使用流控制技术执行。可以使用两种不同的方法将所提出的体系结构应用于支持SDN的移动网络,以提高计算能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号