首页> 外文OA文献 >Mitigating the Table-Overflow Attack in Software-Defined Networking
【2h】

Mitigating the Table-Overflow Attack in Software-Defined Networking

机译:减轻软件定义网络中的表溢出攻击

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。
获取外文期刊封面目录资料

摘要

Software-defined networking (SDN) is a promising network paradigm for future Internet. The centralized controller and simplified switches replace the traditional complex forwarding devices, and make network management convenient. However, the switches in SDN currently have limited ternary content addressable memory (TCAM) to store specific routing rules from the controller. This bottleneck provokes cyber attacks to overload the switches. Despite existing some countermeasures for such attacks, they are proposed based on simplified attack patterns. In this paper, we review the table-overflow attack using a sophisticated attack pattern. In the attack pattern, attack flows are targeted at their middle hops instead of endpoints. We first define potential targets in the network topology, and then we propose three specific traffic features and a monitoring mechanism to detect and locate the attackers. Further, we propose a mitigation mechanism to limit the attack rate using the token bucket model. With the control of token add rate and bucket capacity, it avoids the table overflow on the victim switch. Extensive simulations in different types of topologies and experiments in our testbed are provided to show the performance of our proposal.
机译:软件定义网络(SDN)是未来Internet的有希望的网络范例。集中控制器和简化的交换机取代了传统的复杂转发设备,使网络管理更加便捷。但是,SDN中的交换机当前具有有限的三态内容可寻址存储器(TCAM),用于存储来自控制器的特定路由规则。此瓶颈会引发网络攻击,从而使交换机过载。尽管存在针对此类攻击的一些对策,但它们是基于简化的攻击模式提出的。在本文中,我们使用复杂的攻击模式回顾了表溢出攻击。在攻击模式中,攻击流针对其中间跃点而不是端点。我们首先定义网络拓扑中的潜在目标,然后提出三个特定的流量功能以及一种监视机制,以检测和定位攻击者。此外,我们提出了一种缓解机制,以使用令牌桶模型来限制攻击率。通过控制令牌添加速率和存储桶容量,可以避免受害者交换机上的表溢出。在我们的测试平台中提供了不同类型拓扑和实验的广泛仿真,以显示我们的建议的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号