首页> 外文期刊>IEEE/ACM Transactions on Networking >Network-Wide Forwarding Anomaly Detection and Localization in Software Defined Networks
【24h】

Network-Wide Forwarding Anomaly Detection and Localization in Software Defined Networks

机译:软件定义网络中的网络范围转发异常检测和本地化

获取原文
获取原文并翻译 | 示例
           

摘要

A crucial requirement for Software Defined Network (SDN) is that data plane forwarding behaviors should always agree with control plane policies. Such requirement cannot be met when there are forwarding anomalies, where packets deviate from the paths specified by the controller. Most anomaly detection methods for SDN install dedicated rules to collect statistics of each flow, and check whether the statistics conform to the "flow conservation principle". We find these methods have a limited detection scope: they look at one flow each time, thus can only check a small number of flows simultaneously. In addition, dedicated rules for statistics collection can impose a large overhead on flow tables of SDN switches. To this end, this paper presents FOCES, a network-wide forwarding anomaly detection and localization method in SDN. Different from previous methods, FOCES applies a new kind of flow conservation principle at network wide, and can check forwarding behaviors of all flows in the network simultaneously, without installing any dedicated rules. Finally, FOCES applies a voting-based method to localize malicious switches when anomalies are detected. Experiments with four network topologies show that FOCES can achieve a detection precision higher than 90%, when the packet loss rate is no larger than 10%, and a localization accuracy of around 80% when the packet loss rate is no larger than 5%.
机译:软件定义网络(SDN)的关键要求是数据平面转发行为应始终同意控制平面策略。当存在转发异常时,不能满足此类要求,其中数据包偏离控制器指定的路径。 SDN的大多数异常检测方法安装专用规则以收集每个流程的统计数据,并检查统计数据是否符合“流量守恒原理”。我们发现这些方法有一个有限的检测范围:它们每次看一次流动,因此只能同时检查少量流动。此外,统计收集的专用规则可以在SDN交换机的流量表上强加大量开销。为此,本文介绍了SDN中的网络宽的转发异常检测和定位方法。不同于以前的方法,FOCES在网络广播中应用一种新的流量守恒原理,可以同时检查网络中所有流量的转发行为,而无需安装任何专用规则。最后,FOCES应用基于投票的方法,以在检测到异常时本地化恶意交换机。具有四个网络拓扑的实验表明,当丢包率不大于10%时,FOCE可以实现高于90%的检测精度,并且当丢包率不大于5%时,定位精度约为80%。

著录项

  • 来源
    《IEEE/ACM Transactions on Networking》 |2021年第1期|332-345|共14页
  • 作者单位

    Xi An Jiao Tong Univ Key Lab Intelligent Networks & Network Secur Minist Educ MOE Xian 710049 Peoples R China;

    Xi An Jiao Tong Univ Sch Comp Sci & Technol Xian 710049 Peoples R China;

    Xi An Jiao Tong Univ Sch Comp Sci & Technol Xian 710049 Peoples R China;

    Xi An Jiao Tong Univ Sch Comp Sci & Technol Xian 710049 Peoples R China|Chinese Univ Hong Kong Dept Comp Sci & Engn Hong Kong Peoples R China;

    Xi An Jiao Tong Univ Key Lab Intelligent Networks & Network Secur Minist Educ MOE Xian 710049 Peoples R China;

    Tsinghua Univ Inst Network Sci & Cyberspace Beijing 100084 Peoples R China;

    Xi An Jiao Tong Univ Sch Comp Sci & Technol Xian 710049 Peoples R China;

    Xi An Jiao Tong Univ Key Lab Intelligent Networks & Network Secur Minist Educ MOE Xian 710049 Peoples R China;

    Xi An Jiao Tong Univ Sch Comp Sci & Technol Xian 710049 Peoples R China|Xilinx Labs Asia Pacific Singapore 486040 Singapore;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Control systems; Tools; Anomaly detection; Packet loss; Security; Mathematical model; Software defined network; forwarding anomaly; detection; localization;

    机译:控制系统;工具;异常检测;数据包丢失;安全;数学模型;软件定义网络;转发异常;检测;定位;本地化;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号