首页> 外文会议>IEEE International Conference on Distributed Computing, VLSI, Electrical Circuits and Robotics >Early Detection and Diminution of DDoS attack instigated by compromised switches on the controller in Software Defined Networks
【24h】

Early Detection and Diminution of DDoS attack instigated by compromised switches on the controller in Software Defined Networks

机译:通过软件定义网络中的控制器上的受损开关,可以尽早发现和减少DDoS攻击

获取原文

摘要

Software Defined Networks (SDN) provides separation of data plane and control plane, which can be used for implementing various network solutions like traffic engineering, intrusion detection load balancing, etc. However, there are few issues relating to SDN that needs to be addressed, one of them being Distributed Denial of Service (DDoS) attack on the centralized controller. Many researchers have contributed various solutions for identifying and mitigating such attacks. However, the intruders often find new ways of performing such DDoS attacks and hence the detection of such attacks takes more time and resources. In this paper, the aim is to demonstrate how a DDoS attack can be initiated on an SDN controller by the compromised switches whose idle and hard timeout values are manipulated to send repeated flow table entry requests to the controller. Furthermore, a solution is also proposed to detect such an attack within the second repeated request and mitigate it immediately. This solution is highly efficient as the attack is detected instantly instead of calculating a threshold based on the number of flow entry requests to identify whether the traffic is attack traffic or a genuine one.
机译:软件定义网络(SDN)提供了数据平面和控制平面的分离,可用于实现各种网络解决方案,例如流量工程,入侵检测负载平衡等。但是,与SDN相关的问题很少需要解决,其中之一是对中央控制器的分布式拒绝服务(DDoS)攻击。许多研究人员为识别和缓解此类攻击提供了各种解决方案。但是,入侵者通常会发现执行此类DDoS攻击的新方法,因此检测此类攻击会花费更多时间和资源。在本文中,目的是演示如何通过受到破坏的交换机对SDN控制器发起DDoS攻击,这些交换机的空闲和硬超时值被操纵以向控制器发送重复的流表进入请求。此外,还提出了一种解决方案,以在第二重复请求内检测到这种攻击并立即缓解。该解决方案非常高效,因为可以立即检测到攻击,而不是根据流进入请求的数量来计算阈值以识别流量是攻击流量还是真正流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号