期刊文献+

一种SDN中基于熵值计算的异常流量检测方法 被引量:10

An Entropy Based Anomaly Traffic Detection Approach in SDN
下载PDF
导出
摘要 软件定义网络(software defined networking,SDN)是一种新型网络创新架构,其分离了控制平面与转发平面,使得网络管理更为灵活。借助SDN控制与转发分离的思想,在SDN基础上引入一个集中式安全中心,在数据平面设备上采集数据,用于对网络流量进行分析,通过熵值计算和分类算法判断异常流量行为。对于检测到的网络异常情况,安全中心通过与SDN控制器的接口通告SDN控制器上的安全处理模块,进行流表策略的下发,进而缓解网络异常行为。通过本系统可以在不影响SDN控制器性能的情况下,快速检测网络中的异常行为,并通过SDN下发流表策略对恶意攻击用户进行限制,同时对SDN控制器进行保护。 SDN (software defined networking) is a novel network infrastructure which separate the control plane from the data plane. Taking advantage of the idea of SDN, a central security center was built which collected traffic from the SDN data plane entity for analyzing. The attacks can be detected based on the entropy variation of the identifier and locate the type of attack with the classification algorithm. As the anomaly patterns were detected, the security center would cooperate with the central controller to install the flow table to alleviate the influence of the attack. The anomaly traffic can be detected early and can't influence the performance of the controller. Besides, the controller can be protected from attack based on our system.
出处 《电信科学》 北大核心 2015年第9期83-89,共7页 Telecommunications Science
基金 国家科技重大专项基金资助项目(No.2013ZX03006002) 基本科研业务费资助项目(No.2015YJS028) 国家高技术研究发展计划("863"计划)基金资助项目(No.2015AA015702)~~
关键词 软件定义网络 安全中心 熵值 分布式拒绝服务攻击 SDN, security center, entropy, DDoS
  • 相关文献

参考文献14

  • 1Open Networking Foundation. Software-Defined Networking: the New Norm for Networks, 2012.
  • 2MeKeown N, Anderson T, Balakrishnan H, et al. OpenFlow: enabling innovation in campus networks. Computer Communication Review, 2008, 38(2): 69-74.
  • 3ONF. OpenFlow Switch Specification 1.3.4, 2014.
  • 4Braga R, Mota E, Passito A. Lightweight DDoS flooding attack detection using NOX/OpenFlow. Proceedings of IEEE 35th Conference on Local Computer Networks (LCN), Denver, Colorado, USA, 2010:408-415.
  • 5Mousavi S M, St-Hilaire M. Early detection of DDoS attacks against SDN controllers. Proceedings of 2015 International Conference on Computing, Networking and Communications (ICNC), Ottawa, Canada, 2015:77-81.
  • 6Su W, Wu L, Huang Y, et al. Design of event-based intrusion detection system on OpenFlow network. Proceedings of IEEE International Conference on Dependable Systems and Networks (SDN), Budapest, Hungary, 2013:1N2.
  • 7Giotis K, Argyropoulos C, Androulidakis G, et al. Combining OpenFlow and sFlow for an effective and scalable anomaly detection and mitigation mechanism on SDN environments. Computer Networks, 2014(62): 122-136.
  • 8POX . http://www.noxrepo.org/pox/about-pox/, 2015.
  • 9Hofstede R, Celeda P, Trammell B, et al. Flow monitoring explained: from packet capture to data analysis with NetFlow and IPFIX. IEEE Communications Surveys and Tutorials, 2014, 16(4): 2037-2064.
  • 10Denning D E. An intrusion-detection model. IEEE Transactions on Software Engim.-ering, 1987, 13(2): 222-232.

二级参考文献12

  • 1张亚玲,康立锦.基于数据挖掘的Snort系统改进模型[J].计算机应用,2009,29(2):409-411. 被引量:4
  • 2周涓,熊忠阳,张玉芳,任芳.基于最大最小距离法的多中心聚类算法[J].计算机应用,2006,26(6):1425-1427. 被引量:72
  • 3李洋.K-means聚类算法在入侵检测中的应用[J].计算机工程,2007,33(14):154-156. 被引量:23
  • 4Anderson J P.Computer Security Thread Monitoring and Surveillance[Z].[2009-08-11].http://csrc.nist.gov/publications/history/ande80.pdf.
  • 5Lee W, Stolfo S J.Data mining approaches for intrusion detection[C]//San Antonio T X.Proc 7 USENIX Security Symposium, 1998.
  • 6Sambasivam S, Theodosopoulos N.Adbanced data clustering methods of mining web documents[J].Issues in Informing Science and Information Techology, 2006,8 (3) : 563-579.
  • 7Wu Suyun, Yen E.Data mining-based intrusion deteetors[J].Expert Systems with Applications,2009,36(2):5605-5612.
  • 8Wuu L C,Hung C H, Chen S F.Building intrusion pattern miner for snort network intrusion detection system[J].The Journal of Systems and Software, 2007,80 (2) :1699-1715.
  • 9Corrected.gz[EB/OL].http://kdd.ics.uci.edu/databases/kddcup99/kd-dcup99.html.
  • 10李雷,罗红旗,丁亚丽.一种改进的模糊C均值聚类算法[J].计算机技术与发展,2009,19(12):71-73. 被引量:25

共引文献36

同被引文献114

引证文献10

二级引证文献68

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部