...
首页> 外文期刊>Computers, Materials & Continua >Edge-Computing with Graph Computation: A Novel Mechanism to Handle Network Intrusion and Address Spoofing in SDN
【24h】

Edge-Computing with Graph Computation: A Novel Mechanism to Handle Network Intrusion and Address Spoofing in SDN

机译:用图形计算的边缘计算:一种用于处理SDN的网络入侵和地址欺骗的新机制

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Software Defined Networking (SDN) being an emerging network control model is widely recognized as a control and management platform. This model provides efficient techniques to control and manage the enterprise network. Another emerging paradigm is edge computing in which data processing is performed at the edges of the network instead of a central controller. This data processing at the edge nodes reduces the latency and bandwidth requirements. In SDN, the controller is a single point of failure. Several security issues related to the traditional network can be solved by using SDN central management and control. Address Spoofing and Network Intrusion are the most common attacks. These attacks severely degrade performance and security. We propose an edge computing-based mechanism that automatically detects and mitigates those attacks. In this mechanism, an edge system gets the network topology from the controller and the Address Resolution Protocol (ARP) traffic is directed to it for further analysis. As such, the controller is saved from unnecessary processing related to addressing translation. We propose a graph computation based method to identify the location of an attacker or intruder by implementing a graph difference method. By using the correct location information, the exact attacker or intruder is blocked, while the legitimate users get access to the network resources. The proposed mechanism is evaluated in a Mininet simulator and a POX controller. The results show that it improves system performance in terms of attack mitigation time, attack detection time, and bandwidth requirements.
机译:软件定义的网络(SDN)是新兴网络控制模型被广泛识别为控制和管理平台。该模型提供有效的控制和管理企业网络的技术。另一个新出现的范式是边缘计算,其中在网络的边缘执行数据处理而不是中央控制器。边缘节点处的该数据处理降低了延迟和带宽要求。在SDN中,控制器是单点故障。通过使用SDN中央管理和控制可以解决与传统网络相关的几个安全问题。地址欺骗和网络侵入是最常见的攻击。这些攻击严重降低了性能和安全性。我们提出了一种基于优势计算的机制,可自动检测和减轻这些攻击。在该机制中,边缘系统从控制器获取网络拓扑,地址分辨率协议(ARP)流量被引导到它以进一步分析。因此,控制器从与寻址转换相关的不必要处理中保存。我们提出了一种基于图形计算的方法来识别攻击者或入侵者的位置来实现图形差异方法。通过使用正确的位置信息,确切的攻击者或入侵者被阻止,而合法用户可以访问网络资源。所提出的机制在Mininet模拟器和POX控制器中进行评估。结果表明,它在攻击缓解时间,攻击检测时间和带宽要求方面提高了系统性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号