首页> 外文会议>IEEE Global Communications Conference >SDN-Based DDoS Attack Detection with Cross-Plane Collaboration and Lightweight Flow Monitoring
【24h】

SDN-Based DDoS Attack Detection with Cross-Plane Collaboration and Lightweight Flow Monitoring

机译:跨平台协作和轻量级流量监控的基于SDN的DDoS攻击检测

获取原文

摘要

Distributed Denial of Service (DDoS) attacks are one of the biggest concerns for security professionals. Traditional DDoS attack detection mechanisms are based on middle-box devices or SDN controllers, which either lack network-wide monitoring information or suffer with serious southbound communication overhead and detection delay. In this paper, we propose a SDN-based DDoS attack detection framework with cross-plane collaboration called OverWatch, which performs a two-stage granularity filtering procedure between coarse-grained detection data plane and fine- grained detection control plane for abnormal flows. It leverages computational capabilities that currently underutilized on OpenFlow switches to shrink the detection range for fine-grained DDoS attack detections. In OverWatch, we propose a lightweight flow monitoring algorithm to capture the key features of DDoS attack traffics on the data plane by polling the values of counters in OpenFlow switches. Experiments are conducted in an evaluating network with a FPGA-based OpenFlow switch prototype and the Ryu controller, which reveal that our proposed OverWatch framework and flow monitoring algorithm can greatly improve the detection efficiency, as well as reduce the detection delay and southbound communication overhead.
机译:分布式拒绝服务(DDoS)攻击是安全专业人员最关注的问题之一。传统的DDoS攻击检测机制基于中间盒设备或SDN控制器,它们缺乏网络范围的监视信息,或者遭受严重的南向通信开销和检测延迟。在本文中,我们提出了一种跨平台协作的基于SDN的DDoS攻击检测框架,称为OverWatch,该框架在异常流量的粗粒度检测数据平面和细粒度检测控制平面之间执行两阶段的粒度过滤过程。它利用了当前在OpenFlow交换机上未充分利用的计算功能,以缩小用于细粒度DDoS攻击检测的检测范围。在《守望先锋》中,我们提出了一种轻量级的流量监视算法,通过轮询OpenFlow交换机中计数器的值来捕获数据平面上DDoS攻击流量的关键特征。在基于FPGA的OpenFlow交换机原型和Ryu控制器的评估网络中进行了实验,这表明我们提出的OverWatch框架和流量监视算法可以大大提高检测效率,并减少检测延迟和南向通信开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号