...
首页> 外文期刊>IEEE/ACM Transactions on Networking >SDN-RDCD: A Real-Time and Reliable Method for Detecting Compromised SDN Devices
【24h】

SDN-RDCD: A Real-Time and Reliable Method for Detecting Compromised SDN Devices

机译:SDN-RDCD:一种实时可靠的检测受损SDN设备的方法

获取原文
获取原文并翻译 | 示例

摘要

A software-defined network (SDN) is increasingly deployed in many practical settings, bringing new security risks, e.g., SDN controller and switch hijacking. In this paper, we propose a real-time method to detect compromised SDN devices in a reliable way. The proposed method aims at solving the detection problem of compromised SDN devices when both the controller and the switch are trustless, and it is complementary with existing detection methods. Our primary idea is to employ backup controllers to audit the handling information of network update events collected from the primary controller and its switches, and to detect compromised devices by recognizing inconsistent or unexpected handling behaviors among the primary controller, backup controllers, and switches. Following this idea, we first capture each network update request and its execution result in the primary controller, collect each received network update instruction and the information of any state update in switches, and deliver these four kinds of information to those backup controllers in an auditor role. An auditor controller is designed to create an audit record for each received network update request and to add its execution result of this network update request as well as the received four kinds of matching information to the audit record. In particular, heterogeneous auditor controllers are proposed to avoid the same vulnerability with the primary controller. The audit algorithm and theoretical proof of its effectiveness for security enhancement are then presented. Finally, based on our prototype implementation, our experimental results further validate the proposed method and its low costs.
机译:软件定义网络(SDN)越来越多地部署在许多实际设置中,带来了新的安全风险,例如SDN控制器和交换机劫持。在本文中,我们提出了一种实时方法来以可靠的方式检测受感染的SDN设备。所提出的方法旨在解决控制器和交换机均不信任的情况下受损的SDN设备的检测问题,并与现有的检测方法互补。我们的主要思想是使用备用控制器来审核从主控制器及其交换机收集的网络更新事件的处理信息,并通过识别主控制器,备用控制器和交换机之间的不一致或意外的处理行为来检测受感染的设备。按照这个想法,我们首先在主控制器中捕获每个网络更新请求及其执行结果,收集每个接收到的网络更新指令以及交换机中任何状态更新的信息,并将这四种信息传递给审核员中的那些备用控制器。角色。审计器控制器被设计为为每个接收到的网络更新请求创建审计记录,并将该网络更新请求的执行结果以及接收到的四种匹配信息添加到审计记录中。特别是,提出了异构审计员控制器以避免与主控制器相同的漏洞。然后提出了审计算法及其在安全性方面的有效性的理论证明。最后,基于我们的原型实现,我们的实验结果进一步验证了所提出的方法及其低成本。

著录项

  • 来源
    《IEEE/ACM Transactions on Networking》 |2018年第5期|2048-2061|共14页
  • 作者单位

    Cyber Security Research Institute and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China;

    Cyber Security Research Institute and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China;

    Cyber Security Research Institute and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China;

    Cyber Security Research Institute and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China;

    Cyber Security Research Institute and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China;

    Cyber Security Research Institute and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China;

    Cyber Security Research Institute and the College of Computer Science and Technology, Zhejiang University, Hangzhou, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Switches; Peer-to-peer computing; Security; Fault tolerance; Fault tolerant systems;

    机译:交换机;对等计算;安全性;容错性;容错系统;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号