首页> 外文期刊>IEEE transactions on dependable and secure computing >Dynamic Packet Forwarding Verification in SDN
【24h】

Dynamic Packet Forwarding Verification in SDN

机译:SDN中的动态数据包转发验证

获取原文
获取原文并翻译 | 示例
           

摘要

Like traditional IP networking, the emerging Software-Defined Networking (SDN) technology is vulnerable to sophisticated attacks against packets and their forwarding behaviors. However, existing proposals of packet forwarding verification for IP networking cannot be directly applied to the current SDN deployment due to the limited functionalities and resources in commercial off-the-shelf (COTS) SDN switches. We propose DynaPFV, a dynamic packet forwarding verification mechanism that is capable of detecting various sophisticated attacks against packet forwarding. DynaPFV leverages the controllability of SDN to examine both packets and flow statistics across a network of switches to detect violation of packet integrity and forwarding behaviors. To mitigate the verification overhead, DynaPFV dynamically adjusts the rates of packet sampling and flow statistics collection based on the prior detection results in order to preserve the verification accuracy. Furthermore, DynaPFV makes changes to the SDN controller only, and is directly deployable atop COTS SDN switches without modifications. We conduct theoretical analysis on the trade-off between performance and accuracy in our dynamic verification approach. We further prototype DynaPFV using the open-source Floodlight controller, and evaluate our DynaPFV prototype using Mininet simulations and hardware testbed experiments. DynaPFV achieves over 97 percent of verification accuracy only with less than 5 percent of throughput degradation and less than 10 percent of additional forwarding delays.
机译:与传统IP网络一样,新兴的软件定义网络(SDN)技术容易受到针对数据包及其转发行为的复杂攻击。但是,由于商用现货(COTS)SDN交换机的功能和资源有限,无法将现有的IP网络分组转发验证建议直接应用于当前的SDN部署。我们提出了DynaPFV,这是一种动态的数据包转发验证机制,能够检测各种复杂的针对数据包转发的攻击。 DynaPFV利用SDN的可控性来检查数据包和跨交换机网络的流量统计信息,以检测对数据包完整性和转发行为的违反。为了减轻验证开销,DynaPFV根据先前的检测结果动态调整数据包采样率和流统计信息收集率,以保持验证准确性。此外,DynaPFV仅对SDN控制器进行更改,并且无需修改即可直接部署在COTS SDN交换机上。我们使用动态验证方法对性能和准确性之间的取舍进行理论分析。我们使用开源Floodlight控制器进一步对DynaPFV进行原型设计,并使用Mininet仿真和硬件测试平台实验评估DynaPFV原型。 DynaPFV仅在不到5%的吞吐量下降和不到10%的额外转发延迟的情况下,才能达到97%以上的验证准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号