首页> 外文会议>International Conference on Information and Communication Technology Convergence >SDN-based network security functions for effective DDoS attack mitigation
【24h】

SDN-based network security functions for effective DDoS attack mitigation

机译:基于SDN的网络安全功能可有效缓解DDoS攻击

获取原文

摘要

Distributed Denial of Service (DDoS) attack has been bringing serious security concerns on banks, finance incorporation, public institutions, and data centers. Also, the emerging wave of Internet of Things (IoT) raises new concerns on the smart devices. Software Defined Networking (SDN) and Network Functions Virtualization (NFV) have provided a new paradigm for network security. In this paper, we propose a new method to efficiently prevent DDoS attacks, based on a SDN/NFV framework. To resolve the problem that normal packets are blocked due to the inspection on suspicious packets, we developed a threshold-based method that provides a client with an efficient, fast DDoS attack mitigation. In addition, we use open source code to develop the security functions in order to implement our solution for SDN-based network security functions. The source code is based on NETCONF protocol [1] and YANG Data Model [2].
机译:分布式拒绝服务(DDoS)攻击已经给银行,金融公司,公共机构和数据中心带来了严重的安全隐患。此外,新兴的物联网(IoT)浪潮也引发了对智能设备的新关注。软件定义网络(SDN)和网络功能虚拟化(NFV)为网络安全提供了新的范例。在本文中,我们提出了一种基于SDN / NFV框架的有效防御DDoS攻击的新方法。为了解决由于检查可疑数据包而导致正常数据包被阻止的问题,我们开发了一种基于阈值的方法,该方法可为客户端提供有效,快速的DDoS攻击缓解。此外,我们使用开放源代码来开发安全功能,以便为基于SDN的网络安全功能实现我们的解决方案。源代码基于NETCONF协议​​[1]和YANG数据模型[2]。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号