首页> 外文会议>International Conference on Advanced Technologies for Communications >A multi-criteria-based DDoS-attack prevention solution using software defined networking
【24h】

A multi-criteria-based DDoS-attack prevention solution using software defined networking

机译:使用软件定义网络的基于多标准的DDoS攻击预防解决方案

获取原文

摘要

Software-Defined Networking (SDN) has become a promising network architecture in which network devices are controlled by a SDN Controller. Employing SDN offers an attractive solution for network security. However the attack prediction and Prevention, especially for Distributed Denial of Service (DDoS) attacks is a challenge in SDN environments. This paper, analyzes the characteristics of traffic flows up-streaming to a Vietnamese ISP server, during both states of normal and DDoS attack traffic. Based on the traffic analysis, an SDN-based Attack Prevention Architecture is proposed that is able to capture and analyze incoming flows on-the-fly. A multi-criteria based Prevention mechanism is then designed using both hard-decision thresholds and Fuzzy Inference System to detect DDoS attack. In response to determining the presence of attacks, the designed system is capable of dropping attacks flows, demanding from the control plane.
机译:软件定义网络(SDN)已成为一种有前途的网络体系结构,其中网络设备由SDN控制器控制。使用SDN为网络安全提供了一个有吸引力的解决方案。但是,在SDN环境中,尤其是针对分布式拒绝服务(DDoS)攻击的攻击预测和预防是一个挑战。本文分析了在正常和DDoS攻击流量的两种状态下,流向越南ISP服务器的流量的特征。基于流量分析,提出了一种基于SDN的攻击防御体系结构,该体系结构能够实时捕获和分析传入的流。然后使用硬决策阈值和模糊推理系统设计一种基于多标准的预防机制,以检测DDoS攻击。响应于确定攻击的存在,所设计的系统能够丢弃来自控制平面的攻击流。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号