首页> 外文会议>International Conference on Computing, Networking and Communications >Rapid detection of disobedient forwarding on compromised OpenFlow switches
【24h】

Rapid detection of disobedient forwarding on compromised OpenFlow switches

机译:在受损的OpenFlow交换机上快速检测不听话的转发

获取原文

摘要

Software-defined networking (SDN) allows network administrators to manage network flows easily from a centralized controller. However, it also leads to new security threats to applications, controllers, OpenFlow switches, topology management and so on. In this work, we design a method to detect disobedient forwarding in the flow table by compromising a switch. To enhance detection efficiency and minimize additional network traffic, we reduce the number of detection packets necessary by aggregating the flow entries. This method selects the flow entries whose match fields can compose a valid packet from multiple switches. The switches on which the entries are form a path that allows the packet to travel through for rapid detection. We evaluate the efficiency of this detection method for various topology types in typical data center networks by Mininet simulation. The experimental results demonstrate that this method can examine the forwarding correctness of around 3 flow entries simultaneously for each detection packet in fat-tree topology. Furthermore, the scale of the network topology does not affect the efficiency of the method significantly.
机译:软件定义网络(SDN)使网络管理员可以从集中式控制器轻松管理网络流。但是,这也给应用程序,控制器,OpenFlow交换机,拓扑管理等带来了新的安全威胁。在这项工作中,我们设计了一种通过破坏开关来检测流表中不听从转发的方法。为了提高检测效率并最大程度地减少额外的网络流量,我们通过聚合流条目来减少必要的检测数据包数量。此方法从多个交换机中选择其匹配字段可以组成有效数据包的流条目。条目所在的交换机形成一条路径,该路径允许数据包通过以进行快速检测。我们通过Mininet仿真评估了这种检测方法对于典型数据中心网络中各种拓扑类型的效率。实验结果表明,该方法可以同时针对胖树拓扑中的每个检测包检查3个流条目的转发正确性。此外,网络拓扑的规模不会显着影响该方法的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号