...
首页> 外文期刊>Procedia Computer Science >Secure Multipath Mutation SMPM in Moving Target Defense Based on SDN
【24h】

Secure Multipath Mutation SMPM in Moving Target Defense Based on SDN

机译:基于SDN的移动目标防御中的安全多径变异SMPM

获取原文
           

摘要

Software-defined networking (SDN) refers to a network architecture where the transfer state in the data plane is managed by a remote control plane in a centralized manner. SDN offer many advantage in terms of flexibility and automation to administrator but it suffer from many security issues. In other hand, Random Route Mutation (RRM) and path diversity represent one of the important research focuses about moving target defense (MTD). The main idea of using this technic, is to change periodically (or basing on events) used routes between sender and receiver in order to enhance mutation efficiency and decrease attackers capabilities to launch effective eavesdropping, denial of service or man in the middle attack. Using RRM and multi path technics can be very interesting in order to secure SDN and to detect and prevent intrusions. In this paper it is propose a new framework called SMPM which aims to secure and prevent intrusion by modeling SDN architectures and using a pathfinder algorithm called RRM-Pathfinder. The proposed framework calculates all possible paths from given source to destination and then, based on some criteria such as capacity, Overlap, Security and QoS, it selects and identifies the most cost-effective routes. The use of SMPM allow also to dynamically route packets using all pre-calculated paths which will permit to avoid sniffing and poisoning attacks such as Arp spoof and the man in the middle attacks and to ensure more confidentiality, integrity and privacy.
机译:软件定义网络(SDN)是指一种网络体系结构,其中数据平面中的传输状态由远程控制平面以集中方式进行管理。 SDN在灵活性和自动化方面为管理员提供了许多优势,但是它存在许多安全问题。另一方面,随机路径突变(RRM)和路径多样性代表着有关移动目标防御(MTD)的重要研究之一。使用此技术的主要思想是定期更改(或基于事件)发送方和接收方之间的已用路由,以提高突变效率并降低攻击者在中间攻击中发起有效的窃听,拒绝服务或人工攻击的能力。为了保护SDN并检测和防止入侵,使用RRM和多路径技术可能非常有趣。在本文中,提出了一个名为SMPM的新框架,该框架旨在通过对SDN架构进行建模并使用称为RRM-Pathfinder的路径查找器算法来保护和防止入侵。拟议的框架计算从给定源到目的地的所有可能路径,然后基于容量,重叠,安全性和QoS等标准,选择并确定最具成本效益的路由。 SMPM的使用还允许使用所有预先计算的路径动态路由数据包,这将避免嗅探和中毒攻击,例如Arp欺骗和中间人攻击,并确保更高的机密性,完整性和私密性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号