首页> 外文会议>IEEE International Conference on Computer and Communications >Democratic Supervision Makes Controls in Software-Defined Networks More Secure
【24h】

Democratic Supervision Makes Controls in Software-Defined Networks More Secure

机译:民主监督使软件定义网络中的控制更加安全

获取原文

摘要

The centralized control of Software-Defined Networking (SDN) brings innovation and convenience to the network, but many current SDN controllers also have some security bugs that are easily exploited by attackers. Once the master controller which has sufficient management rights is compromised, entire network can be damaged. For this, we propose a mechanism of democratic supervision in SDN, which adds a proxy between the control plane and the data plane to monitor whether the master controller is abnormal. The proxy sends OpenFlow requests from the switch to multiple diverse controllers and collects flow entries that they respond to. Then it compares these flow entries to judge whether the behavior of the master controller is different from that of other controllers. However, flow entries with the same function may be different in number or content, so we need to analyze their forwarding semantics to compare them, instead of simply comparing their contents. The advantage of this supervision mechanism is that it allows the controller to defend against many known or unknown attacks without debugging all its vulnerabilities. Experimental results show that it is effective in detecting malicious behavior, and it is also efficient under a certain scale of networks.
机译:软件定义网络(SDN)的集中控制为网络带来了创新和便利,但是许多当前的SDN控制器也存在一些容易被攻击者利用的安全漏洞。一旦具有足够管理权限的主控制器受到威胁,整个网络就会受到破坏。为此,我们提出了SDN中的民主监督机制,该机制在控制平面和数据平面之间添加代理以监视主控制器是否异常。代理将来自交换机的OpenFlow请求发送到多个不同的控制器,并收集它们响应的流条目。然后,它将比较这些流条目,以判断主控制器的行为是否与其他控制器的行为不同。但是,具有相同功能的流条目的数量或内容可能有所不同,因此我们需要分析其转发语义以进行比较,而不是简单地比较其内容。这种监视机制的优点在于,它允许控制器防御许多已知或未知的攻击,而无需调试其所有漏洞。实验结果表明,该方法在检测恶意行为方面是有效的,并且在一定规模的网络下也有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号