首页> 外文会议>IEEE/IFIP Network Operations and Management Symposium >Fast address hopping at the switches: Securing access for packet forwarding in SDN
【24h】

Fast address hopping at the switches: Securing access for packet forwarding in SDN

机译:交换机上的快速地址跳变:在SDN中保护数据包转发的访问安全

获取原文

摘要

To defend against network reconnaissance for unauthorized access of the packet forwarding path, we leverage software-defined networking (SDN) and build moving target defense (MTD) by randomizing network addresses. We distinguish our work from prior research by implementing MTD at the data plane and on all nodes along the forwarding path. Thus, our scheme is fast and lightweight in operation (significantly decreasing the controller communication overhead) and enables quicker security response to reduce the attack impact (as opposed to having the attack impact all the way to the endhost destination). We validate our work on an Open vSwitch-based testbed and show that the attacker's cost to achieve timely network reconnaissance increases by more than an order of magnitude than having the controller actuate the MTD.
机译:为了防御未经授权访问数据包转发路径的网络侦查,我们利用软件定义的网络(SDN)并通过随机分配网络地址来构建移动目标防御(MTD)。通过在数据平面和转发路径上的所有节点上实现MTD,我们将我们的工作与先前的研究区分开来。因此,我们的方案操作快速,轻便(显着减少了控制器的通信开销),并且能够实现更快的安全响应,从而减少了攻击的影响(与一直到终端主机目的地的攻击影响相反)。我们在基于Open vSwitch的测试床上验证了我们的工作,并表明,与使控制器启动MTD相比,攻击者实现及时网络侦察的成本增加了一个数量级。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号