首页> 外文会议>International Conference on Networking and Network Applications >Experimental Security Analysis of SDN Network by Using Packet Sniffing and Spoofing Technique on POX and Ryu Controller
【24h】

Experimental Security Analysis of SDN Network by Using Packet Sniffing and Spoofing Technique on POX and Ryu Controller

机译:用痘和RYU控制器使用包嗅探和欺骗技术对SDN网络的实验安全性分析

获取原文

摘要

Software-Defined Networking (SDN) is an emerging network system which can configure and control the network by using programming technique through the specific controller (On the basis of Control Plane) to control whole network system. In this network system, the control plane and data plane are separated from each other through a specific controller such as Ryu, POX and OpenDayLight controller etc. In this network, the attacker could sniff or spoof the traffic by compromising SDN controllers and may utilize the entire network resources and may damage the entire network system which, in fact, should be disallowed by the controller. Therefore, in this research, we conducted an experiment to demonstrate how to mitigate such kinds of SDN attacks on both POX and Ryu controller separately to establish a secured network through a remotely operated SDN controller. In this research, we conducted two major experiments. Firstly, we conducted the layer 2 security on POX controller. Secondly, we conducted layer 3 security on Ryu controller. To analyze the layer 3 security functionalities of Ryu controller, we set some rules on the controller to filter the packets according to their packet type. Finally, we ensured that Ryu is one of the most comprehensive programmable controllers to provide the security features on SDN to develop firewall application in the future and offer future research direction.
机译:软件定义的网络(SDN)是一种新兴网络系统,它可以通过使用规划技术通过特定控制器(基于控制平面)来配置和控制网络来控制整个网络系统。在该网络系统中,控制平面和数据平面通过诸如Ryu,Pox和OpenDaylight控制器等的特定控制器彼此分离,攻击者可以通过影响SDN控制器嗅探或欺骗流量,并且可以利用整个网络资源可能会损坏整个网络系统,实际上应该被控制器不允许。因此,在这项研究中,我们进行了一个实验,以便如何分别通过远程操作的SDN控制器建立安全网络的诸如POX和RYU控制器上的这些类型的SDN攻击。在这项研究中,我们进行了两个主要实验。首先,我们在POX控制器上进行了第2层安全性。其次,我们在RYU控制器上进行了第3层安全性。要分析Ryu控制器的第3层安全功能,我们在控制器上设置了一些规则,以根据其数据包类型来过滤数据包。最后,我们确保Ryu是最全面的可编程控制器之一,以便在SDN上提供安全功能,以在将来开发防火墙应用,并提供未来的研究方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号