...
首页> 外文期刊>IEEE transactions on network and service management >BWManager: Mitigating Denial of Service Attacks in Software-Defined Networks Through Bandwidth Prediction
【24h】

BWManager: Mitigating Denial of Service Attacks in Software-Defined Networks Through Bandwidth Prediction

机译:BWManager:通过带宽预测缓解软件定义网络中的拒绝服务攻击

获取原文
获取原文并翻译 | 示例

摘要

Software-defined networking (SDN) has emerged as a new networking paradigm that can provide fine-grained network management service. Since the SDN controller makes control decision for the network, it becomes the main target of denial of service (DoS) attacks. In this paper, we propose BWManager to mitigate... which mainly consists mitigate the DoS attacks on the SDN controller with BWManager that mainly consists of four key components: 1) simplified DoS detection module; 2) forecasting engine; 3) priority manager; and 4) scheduler. The simplified DoS detection module calculates a comprehensive judgment score for each switch, which indicates the attacking severity of each switch and is used to decide time slice allocation of the controller. The forecasting engine is the basis of the controller scheduling method and forecasts the bandwidth consumption of users to determine the users’ trust values. The trust values are used by the priority manager to manage multiple buffer queues with different priorities for the users. The scheduler protects the controller and the normal users under DoS attacks by running a weighted Round-Robin algorithm to process flow requests in different priority queues. We evaluate the performance and overhead of BWManager in both hardware and software OpenFlow environments. The results demonstrate that BWManager is effective with a limited overhead.
机译:软件定义网络(SDN)已经成为一种新的网络范例,可以提供细粒度的网络管理服务。由于SDN控制器为网络做出控制决策,因此它成为拒绝服务(DoS)攻击的主要目标。在本文中,我们提出了BWManager来减轻...主要包括使用BWManager减轻SDN控制器上的DoS攻击,BWManager主要包括四个关键组件:1)简化的DoS检测模块; 2)预测引擎; 3)优先级管理器;和4)调度程序。简化的DoS检测模块为每个交换机计算综合判断评分,该评分表明每个交换机的攻击严重程度,并用于确定控制器的时间片分配。预测引擎是控制器调度方法的基础,可以预测用户的带宽消耗以确定用户的信任值。优先级管理器使用信任值来为用户管理具有不同优先级的多个缓冲区队列。调度程序通过运行加权循环算法来处理不同优先级队列中的流请求,从而在DoS攻击下保护控制器和普通用户。我们在硬件和软件OpenFlow环境中评估BWManager的性能和开销。结果表明,BWManager在有限的开销下是有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号