首页> 外文会议>IEEE Symposium on Computers and Communications >SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment
【24h】

SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment

机译:SDNSCORE:在SDN环境中对DDOS攻击的统计防御机制

获取原文

摘要

Software Defined Networking (SDN) is a promising solution for addressing challenges of future networks. Despite its advantages such as flexibility, simplification and low costs, it has several drawbacks that are largely induced by the centralized control paradigm. Security is one of the most significant challenges related to centralization. In that regard, Distributed Denial of Service (DDoS) attacks pose crucial security questions in software-defined networks. In SDN architecture, switches send all packets to the controller if they do not have any applicable rules in their flow tables. Basically, controller is the key place that can take initiative in decisions. However, this characteristic results in large communication overhead and delay until a DDoS attack is detected and an appropriate action is activated against attack packets. Therefore, in this work we propose a hybrid mechanism, namely SDNScore, where switches are not simply data forwarders. Instead, they can collect statistics and decide if DDoS attack is in action. Then they coordinate with the controller and act on attack packets in cooperation. SDNScore is a statistical and packet-based defense mechanism against DDoS attacks in SDN environment. Since it has a statistical scoring method, it can detect not only known but also unknown attacks entailing packets that are alike in terms of TCP and IP layer properties. In addition, it does not drop all packets in a flow which includes both attack and legal packets, but rather filters out attack packets using packet-based analysis.
机译:软件定义的网络(SDN)是解决未来网络挑战的有希望的解决方案。尽管其优势如灵活性,简化和低成本,但它具有几个缺点,这些缺点在很大程度上被集中控制范例诱导。安全是与集中化有关的最重要挑战之一。在这方面,分布式拒绝服务(DDOS)攻击在软件定义的网络中造成了重要的安全问题。在SDN架构中,如果在流量表中没有任何适用规则,则交换机将所有数据包发送到控制器。基本上,控制器是可以在决策中获取主动的关键位置。然而,这种特性导致大的通信开销和延迟,直到检测到DDOS攻击并且激活适当的动作,反对攻击分组。因此,在这项工作中,我们提出了一个混合机制,即SDNScore,其中交换机不仅仅是数据转发器。相反,他们可以收集统计数据并决定DDOS攻击是否正在采取行动。然后他们与控制器协调并在合作中进行攻击数据包。 SDNScore是一个统计和基于数据包的防御机制,免于DDOS攻击SDN环境。由于它具有统计评分方法,因此它不仅可以检测到已知但也可以在TCP和IP层属性方面不知所用地攻击所需的数据包。此外,它不会将所有数据包放入包含攻击和法律数据包的流中,而是使用基于分组的分析来筛选出攻击分组。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号