首页> 外文期刊>Information >SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
【24h】

SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks

机译:基于SDN的入侵检测系统,可早期发现和缓解DDoS攻击

获取原文
           

摘要

The current paper addresses relevant network security vulnerabilities introduced by network devices within the emerging paradigm of Internet of Things (IoT) as well as the urgent need to mitigate the negative effects of some types of Distributed Denial of Service (DDoS) attacks that try to explore those security weaknesses. We design and implement a Software-Defined Intrusion Detection System (IDS) that reactively impairs the attacks at its origin, ensuring the “normal operation” of the network infrastructure. Our proposal includes an IDS that automatically detects several DDoS attacks, and then as an attack is detected, it notifies a Software Defined Networking (SDN) controller. The current proposal also downloads some convenient traffic forwarding decisions from the SDN controller to network devices. The evaluation results suggest that our proposal timely detects several types of cyber-attacks based on DDoS, mitigates their negative impacts on the network performance, and ensures the correct data delivery of normal traffic. Our work sheds light on the programming relevance over an abstracted view of the network infrastructure to timely detect a Botnet exploitation, mitigate malicious traffic at its source, and protect benign traffic.
机译:本文探讨了新兴的物联网(IoT)范式中网络设备引入的相关网络安全漏洞,以及迫切需要减轻试图探索的某些类型的分布式拒绝服务(DDoS)攻击的负面影响这些安全弱点。我们设计并实施了一个软件定义的入侵检测系统(IDS),可以从根本上削弱攻击,从而确保网络基础结构的“正常运行”。我们的建议包括一个IDS,该IDS可自动检测到几种DDoS攻击,然后在检测到攻击时将其通知软件定义网络(SDN)控制器。当前的建议还从SDN控制器向网络设备下载了一些方便的流量转发决策。评估结果表明,我们的建议书及时发现了基于DDoS的多种类型的网络攻击,减轻了它们对网络性能的负面影响,并确保正常流量的正确数据传输。我们的工作通过网络基础结构的抽象视图揭示了编程的相关性,以便及时检测到僵尸网络的利用,从源头上减轻恶意流量并保护良性流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号