首页> 外文期刊>Journal of ambient intelligence and humanized computing >Distributed denial of service (DDoS) attack mitigation in software defined network (SDN)-based cloud computing environment
【24h】

Distributed denial of service (DDoS) attack mitigation in software defined network (SDN)-based cloud computing environment

机译:基于软件定义网络(SDN)的云计算环境中的分布式拒绝服务(DDoS)攻击缓解

获取原文
获取原文并翻译 | 示例

摘要

In recent time, software defined networking (SDN) has evolved into a new and promising networking paradigm. In the SDN-based cloud, the essential features of SDN, including global view of the whole network, software-based traffic analysis, centralized control over the network, etc. can greatly improve the DDoS attack detection and mitigation capabilities of the cloud. However, integration of SDN in the cloud itself introduces new DDoS attack vulnerabilities. Limited flow-table size is a vulnerability that can be exploited by the adversaries to perform DDoS attacks on the SDN-based cloud. In this paper, we first discuss various essential features of SDN that makes it a suitable networking technology for cloud computing. In addition, we represent the flow table-space of a switch by using a queuing theory based mathematical model. Further, we propose a novel flow-table sharing approach to protect the SDN-based cloud from flow table overloading DDoS attacks. This approach utilizes idle flow-table of other OpenFlow switches in the network to protect the switch's flow-table from overloading. Our approach increases the resistance of the cloud system against DDoS attacks with minimal involvement of the SDN controller. Thus, it has very low communication overhead. Our claims are well supported by the extensive simulation-based experiments.
机译:近年来,软件定义网络(SDN)已发展成为一种崭新的有前途的网络范例。在基于SDN的云中,SDN的基本功能,包括整个网络的全局视图,基于软件的流量分析,对网络的集中控制等,可以极大地提高云的DDoS攻击检测和缓解能力。但是,SDN在云本身中的集成会引入新的DDoS攻击漏洞。受限的流表大小是一个漏洞,攻击者可以利用此漏洞在基于SDN的云上执行​​DDoS攻击。在本文中,我们首先讨论SDN的各种基本功能,使其成为适用于云计算的网络技术。此外,我们使用基于排队论的数学模型来表示交换机的流表空间。此外,我们提出了一种新颖的流表共享方法,以保护基于SDN的云免受流表过载DDoS攻击。此方法利用网络中其他OpenFlow交换机的空闲流表来保护交换机的流表免于过载。我们的方法通过最小化SDN控制器的介入来提高云系统抵抗DDoS攻击的能力。因此,它具有非常低的通信开销。广泛的基于模拟的实验充分支持了我们的主张。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号