首页> 外文会议>International Conference on Information and Communication Technology >Design and Implementation Adaptive Intrusion Prevention System (IPS) for Attack Prevention in Software-Defined Network (SDN) Architecture
【24h】

Design and Implementation Adaptive Intrusion Prevention System (IPS) for Attack Prevention in Software-Defined Network (SDN) Architecture

机译:软件定义网络(SDN)架构中用于攻击防御的自适应入侵防御系统(IPS)的设计与实现

获取原文

摘要

Intrusion Prevention System (IPS) is a tool for securing networks from any malicious packet that could be sent from specific host. IPS can be installed on SDN network that has centralized logic architecture, so that IPS doesnt need to be installed on lots of nodes instead it has to be installed alongside the controller as center of logic network. IPS still has a flaw and that is the block duration would remain the same no matter how often a specific host attacks. For this reason, writer would like to make a system that not only integrates IPS on the SDN, but also designs an adaptive IPS by utilizing a fuzzy logic that can decide how long blocks are based on the frequency variable and type of attacks. From the results of tests that have been done, SDN network that has been equipped with adaptive IPS has the ability to detect attacks and can block the attacker host with the duration based on the frequency and type of attacks. The final result obtained is to make the SDN network safer by adding 0.228 milliseconds as the execute time required for the fuzzy algorithm in one process.
机译:入侵防御系统(IPS)是一种工具,用于保护网络免受可能从特定主机发送的任何恶意数据包的攻击。 IPS可以安装在具有集中式逻辑体系结构的SDN网络上,因此IPS不需要安装在许多节点上,而必须与作为逻辑网络中心的控制器一起安装。 IPS仍然存在一个缺陷,那就是无论特定主机攻击多久,一次阻止时间都将保持不变。因此,作者希望创建一个不仅可以在SDN上集成IPS的系统,还可以利用模糊逻辑设计自适应IPS,该模糊逻辑可以根据频率变量和攻击类型来确定多长时间。根据已完成的测试结果,配备有自适应IPS的SDN网络具有检测攻击的能力,并且可以根据攻击的频率和类型在持续时间内阻止攻击者主机。获得的最终结果是,通过在一个过程中增加0.228毫秒作为模糊算法所需的执行时间,可以使SDN网络更加安全。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号