首页> 外文会议>IEEE/IFIP Network Operations and Management Symposium >Fast address hopping at the switches: Securing access for packet forwarding in SDN
【24h】

Fast address hopping at the switches: Securing access for packet forwarding in SDN

机译:交换机上的快速地址跳跳:在SDN中保护数据包转发的访问权限

获取原文
获取外文期刊封面目录资料

摘要

To defend against network reconnaissance for unauthorized access of the packet forwarding path, we leverage software-defined networking (SDN) and build moving target defense (MTD) by randomizing network addresses. We distinguish our work from prior research by implementing MTD at the data plane and on all nodes along the forwarding path. Thus, our scheme is fast and lightweight in operation (significantly decreasing the controller communication overhead) and enables quicker security response to reduce the attack impact (as opposed to having the attack impact all the way to the endhost destination). We validate our work on an Open vSwitch-based testbed and show that the attacker's cost to achieve timely network reconnaissance increases by more than an order of magnitude than having the controller actuate the MTD.
机译:为了防御网络侦察,以便未经授权访问数据包转发路径,我们利用软件定义的网络(SDN)并通过随机化网络地址构建移动目标防御(MTD)。我们通过在数据平面上实施MTD和沿着转发路径的所有节点来区分我们的工作。因此,我们的方案在操作中快速轻轻(显着降低了控制器通信开销),并且能够更快的安全响应来减少攻击影响(而不是使攻击影响一直到终端表达目的地)。我们在基于开放的vswitch的测试平台上验证了我们的工作,并表明攻击者实现及时网络侦察的成本比具有控制器致动机的致动机的数量级增加了多个数量级。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号