首页> 外文期刊>Journal of network and computer applications >SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks
【24h】

SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks

机译:SD-Anti-DDoS:软件定义网络中的快速高效的DDoS防御

获取原文
获取原文并翻译 | 示例

摘要

In order to overcome Distributed Denial of Service (DDoS) in Software Defined Networking (SDN), this paper proposes a mechanism consisting of four modules, namely attack detection trigger, attack detection, attack traceback and attack mitigation. The trigger of attack detection mechanism is introduced for the first time to respond more quickly against DDoS attack and reduce the workload of controllers and switches. In the meantime, the DDoS attack detection method based on neural network is implemented to detect attack. Furthermore, an attack traceback method taking advantages of the characteristics of SDN is also proposed. Meanwhile, a DDoS mitigation mechanism including attack blocking and flow table cleaning is presented. The proposed mechanism is evaluated on SDN testbed. Experimental results show that the proposed mechanism can quickly initiate the attack detection with less than one second and accurately trace the attack source. More importantly, it can block the attack in source and release the occupied resources of switches. (C) 2016 Elsevier Ltd. All rights reserved.
机译:为了克服软件定义网络(SDN)中的分布式拒绝服务(DDoS),提出了一种由攻击检测触发,攻击检测,攻击溯源和攻击缓解四个模块组成的机制。首次引入攻击检测触发机制,可以更快地响应DDoS攻击并减少控制器和交换机的工作量。同时,实现了基于神经网络的DDoS攻击检测方法。此外,还提出了一种利用SDN特性的攻击溯源方法。同时,提出了一种DDoS缓解机制,包括攻击阻止和流表清理。该机制在SDN测试平台上进行了评估。实验结果表明,该机制可以在不到一秒的时间内快速启动攻击检测,并能准确追踪攻击源。更重要的是,它可以阻止源攻击并释放交换机所占用的资源。 (C)2016 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号