首页> 外文期刊>Computers & Security >CIPA: A collaborative intrusion prevention architecture for programmable network and SDN
【24h】

CIPA: A collaborative intrusion prevention architecture for programmable network and SDN

机译:CIPA:针对可编程网络和SDN的协作式入侵防御架构

获取原文
获取原文并翻译 | 示例

摘要

Coordinated intrusion, like DDoS, Worm outbreak and Botnet, is a major threat to network security nowadays and will continue to be a threat in the future. To ensure the Internet security, effective detection and mitigation for such attacks are indispensable. In this paper, we propose a novel collaborative intrusion prevention architecture, i.e. CIPA, aiming at confronting such coordinated intrusion behavior. CIPA is deployed as a virtual network of an artificial neural net over the substrate of networks. Taking advantage of the parallel and simple mathematical manipulation of neurons in a neural net, CIPA can disperse its lightweight computation power to the programmable switches of the substrate. Each programmable switch virtualizes one to several neurons. The whole neural net functions like an integrated IDS/IPS. This allows CIPA to detect distributed attacks on a global view. Meanwhile, it does not require high communication and computation overhead. It is scalable and robust. To validate CIPA, we have realized a prototype on Software-Defined Networks. We also conducted simulations and experiments. The results demonstrate that CIPA is effective.
机译:像DDoS,蠕虫爆发和僵尸网络这样的协调入侵是当今对网络安全的主要威胁,并且在将来仍将是威胁。为了确保Internet的安全性,有效检测和缓解此类攻击是必不可少的。在本文中,我们提出了一种新颖的协作式入侵防御架构,即CIPA,旨在应对这种协调的入侵行为。 CIPA被部署为网络基础上的人工神经网络的虚拟网络。利用神经网络中神经元的并行和简单数学运算优势,CIPA可以将其轻量级的计算能力分散到基板的可编程开关上。每个可编程开关虚拟化一个到几个神经元。整个神经网络的功能类似于集成的IDS / IPS。这使CIPA可以在全局视图上检测分布式攻击。同时,它不需要很高的通信和计算开销。它具有可扩展性和鲁棒性。为了验证CIPA,我们已经在软件定义的网络上实现了原型。我们还进行了模拟和实验。结果证明CIPA是有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号