...
首页> 外文期刊>International Journal of Network Management >A holistic approach to mitigating DoS attacks in SDN networks
【24h】

A holistic approach to mitigating DoS attacks in SDN networks

机译:缓解SDN网络中DoS攻击的整体方法

获取原文
获取原文并翻译 | 示例

摘要

Software-defined networking (SDN) has recently emerged as a new networking technology offering an unprecedented programmability that allows network operators to dynamically manage their infrastructures. However, despite these benefits, deny-of-service (DoS) attacks are considered a major threat to such networks, as they can easily overload the SDN controller and flood switch forwarding tables, resulting in a critical degradation of the network performance. To address this issue, we propose SDN-Guard, a novel holistic approach to protect SDN networks against DoS attacks. Software-defined networking-Guard leverages an intrusion detection system (IDS) to detect potential DoS attacks and then efficiently mitigate their impact by dynamically (1) rerouting malicious traffic, (2) adjusting flow time-outs, and (3) aggregating flow rules. This paper extends our previous work by proposing solutions to minimize the switch-to-IDS traffic without impacting the IDS accuracy. We hence propose to use sampling techniques and devise an integer linear program to find the optimal placement for the IDS and to determine the switches that should mirror the flows towards it so as to minimize network bandwidth consumption. Extensive experiments using Mininet show that SDN-Guard maintains network performance during DoS attacks and succeeds in reducing by up to 32% their impact on controller performance, usage of switch forwarding tables, and control plane bandwidth. Furthermore, our results show that carefully placing the IDS and selecting the switches mirroring, the traffic can reduce by up to 90% the switch-to-IDS traffic. They also show that the IDS accuracy remains at 100% by analyzing only 11% of the network traffic.
机译:软件定义网络(SDN)最近作为一种新的网络技术出现,提供了前所未有的可编程性,允许网络运营商动态管理其基础架构。但是,尽管有这些好处,但拒绝服务(DoS)攻击仍被认为是对此类网络的主要威胁,因为它们很容易使SDN控制器和泛洪交换机转发表超载,从而导致网络性能严重下降。为解决此问题,我们提出了SDN-Guard,这是一种新颖的整体方法,可保护SDN网络免受DoS攻击。软件定义的网络-Guard利用入侵检测系统(IDS)来检测潜在的DoS攻击,然后通过动态(1)重新路由恶意流量,(2)调整流超时以及(3)汇总流规则来有效地减轻其影响。本文通过提出解决方案以在不影响IDS准确性的情况下最大程度地减少切换到IDS的流量,从而扩展了我们以前的工作。因此,我们建议使用采样技术并设计一个整数线性程序来找到IDS的最佳位置,并确定应该向其镜像流的交换机,以最大程度地减少网络带宽消耗。使用Mininet进行的大量实验表明,SDN-Guard在DoS攻击期间保持了网络性能,并成功地将其对控制器性能,交换机转发表的使用和控制平面带宽的影响降低了32%。此外,我们的结果表明,仔细放置IDS并选择交换机进行镜像,流量可以最多减少90%的交换机到IDS流量。他们还表明,仅通过分析11%的网络流量,IDS准确性就可以保持100%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号