首页> 外文会议>IEEE International Conference on Communications >Virtualized network views for localizing misbehaving sources in SDN data planes
【24h】

Virtualized network views for localizing misbehaving sources in SDN data planes

机译:虚拟化网络视图,用于本地化SDN数据平面中行为异常的源

获取原文

摘要

In this paper, we present VISKA, a Cloud security service for detecting malicious switching elements in software defined networking (SDN) environments. VISKA leverages network virtualization and secure probabilistic sketching to isolate misbehaving switches in the underlying SDN network data plane. The main contribution lies in utilizing network virtualization in SDN environments to dynamically isolate parts of the data plane and check their forwarding behavior. This is achieved by applying a set of focused packet probing and sketching mechanisms on virtualized network views mapped to these data plane partitions instead of focusing the security mechanisms on the whole physical network. VISKA flexibly analyzes the network behavior of the granular virtual views and recursively partitions these views to reduce the problem size in order to localize abnormal/malicious network switching units. A test bed prototype implementation is realized on the OpenVirtex SDN network virtualization platform. The experimental analysis corroborated the algorithm's convergence property using the linear and FatTree topologies with SDN network sizes of up to 250 switching units.
机译:在本文中,我们提出了VISKA,一种云安全服务,用于检测软件定义网络(SDN)环境中的恶意交换元素。 VISKA利用网络虚拟化和安全的概率素描来隔离基础SDN网络数据平面中行为异常的交换机。主要贡献在于在SDN环境中利用网络虚拟化来动态隔离数据平面的各个部分并检查其转发行为。这是通过在映射到这些数据平面分区的虚拟化网络视图上应用一组集中的数据包探测和草图绘制机制来实现的,而不是将安全机制集中在整个物理网络上。 VISKA可以灵活地分析颗粒状虚拟视图的网络行为,并对这些视图进行递归分区以减小问题的大小,以便定位异常/恶意网络交换单元。在OpenVirtex SDN网络虚拟化平台上实现了测试平台原型的实现。实验分析使用线性网络和FatTree拓扑(SDN网络大小最多为250个交换单元)证实了算法的收敛性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号