首页> 外文会议>IEEE International Conference on Communications >A cost-effective shuffling-based defense against HTTP DDoS attacks with SDN/NFV
【24h】

A cost-effective shuffling-based defense against HTTP DDoS attacks with SDN/NFV

机译:具有成本效益的基于改组的SDN / NFV防御HTTP DDoS攻击

获取原文
获取外文期刊封面目录资料

摘要

Software-Defined Networking and Network Function Virtualisation (SDN/NFV) can provide flexible resource allocation to support innovative security solutions in a central manner. To mitigate HTTP DDoS attacks, shuffling-based moving target defense has been regarded as one of the most effective ways by redirecting user traffic among a group of virtualized service functions. However, previous work did not notice that frequent changes of user traffic will significantly intensify the control overhead of SDN. In this paper, therefore, we first model the effectiveness and cost for shuffling in SDN/NFV networking with Multi-Objective Markov Decision Processes to find the optimal tradeoff between the effectiveness and cost. We then propose a cost-effective approximation algorithm with a guarantee performance bound to solve the problem. Simulation and implementation on an experimental SDN/NFV network manifest that, given 100 attackers among 1000 users and 50 virtualized functions of a web service, our algorithm achieves the approximation ratio of 0.68 and imposes only 2.4s rule modification latency for each shuffle.
机译:软件定义的网络和网络功能虚拟化(SDN / NFV)可以提供灵活的资源分配,以集中方式支持创新的安全解决方案。为了减轻HTTP DDoS攻击,通过在一组虚拟化服务功能之间重定向用户流量,基于混洗的移动目标防御已被视为最有效的方法之一。但是,以前的工作并未注意到用户流量的频繁变化会显着增加SDN的控制开销。因此,在本文中,我们首先使用多目标马尔可夫决策过程对SDN / NFV网络中改组的有效性和成本进行建模,以找到有效性和成本之间的最佳折衷方案。然后,我们提出了一种具有保证性能的具有成本效益的近似算法,可以解决该问题。在实验性SDN / NFV网络上的仿真和实现表明,给定1000个用户中的100个攻击者和Web服务的50个虚拟化功能,我们的算法可达到0.68的近似比率,并且每次随机播放仅施加2.4s的规则修改延迟。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号