期刊文献+

基于软件定义网络的DDoS攻击检测方法及其应用 被引量:17

Detection Method of DDoS Attack Based on Software Defined Network and Its Application
下载PDF
导出
摘要 根据分布式拒绝服务(DDoS)攻击特性与OpenFlow技术,提出一种基于软件定义网络(SDN)的DDoS攻击检测方法。获取OpenFlow交换机中安装的流表项,构建针对目的地址的流表特征值,并采用支持向量机对训练样本进行分类,实现DDoS攻击的检测。通过将该DDoS攻击检测方法进行原型系统实现并集成到SDN网络环境中,验证了该方法的正确性和有效性,并表明其能在提高DDoS攻击行为检测率的同时明显降低误报率,具有较好的综合检测性能。 According to the characteristics of Distributed Denial of Service( DDoS) attack and Open Flow technology,this paper proposes a novel DDoS attack detection method based on Softw are Defined Network( SDN). It gets flow-table item installed in Open Flow switch,constructs the effective global network flow-table characteristic values for destination address,and classifies the training sample by using Support Vector Machine( SVM) to realize DDoS attack on-line detection. It implements prototype system of DDoS attack detection methods and makes it integrate into the SDN environment to verify the correctness and validity of the method. Experimental result shows that this method can improve the DDoS attack Detection Rate( DR) and decrease False Alarm Rate( FR),and it has good comprehensive performance.
出处 《计算机工程》 CAS CSCD 北大核心 2016年第2期118-123,共6页 Computer Engineering
基金 上海市科技创新行动计划基金资助项目"基于开放架构的高可靠软件定义网络体系研究"(13511500400)
关键词 软件定义网络 OpenFlow技术 分布式拒绝服务 流表特征值 监督学习算法 攻击检测 Software Defined Network(SDN) Open Flow technology Distributed Denial of Service(DDoS) flow-table characteristic value supervised learning algorithm attack detection
  • 相关文献

参考文献13

  • 1张永铮,肖军,云晓春,王风宇.DDoS攻击检测和控制方法[J].软件学报,2012,23(8):2058-2072. 被引量:117
  • 2Zander S,Nguyen T,Armitage G.Automated Traffic Classification and Application Identification Using Machine Learning[C]//Proceedings of CLCN’05.Washington D.C.,USA:IEEE Computer Society Press,2005:250-257.
  • 3Liu Yun,Cheng Jieren,Yin Jianping,et al.Anomaly Detection for DDo S Attacks via Behavior Profiles Deviation Degree[C]//Proceedings of the 3rd International Conference on Computer Design and Applications.Washington D.C.,USA:IEEE Press,2011:13278-13282.
  • 4Phillip P,Seungwon S,Vinod Y,et al.A Security Enforcement Kernel for Open Flow Networks[C]//Proceedings of the 1st Workshop on Hot Topics in Software Defined Networks.New York,USA:ACM Press,2012:121-126.
  • 5Mc Keown N,Anderson T,Balakrishnan H.Open Flow:Enabling Innovation in Campus Networks[J].ACM SIGCOMM Computer Communication Review,2008,38(2):69-74.
  • 6左青云,陈鸣,赵广松,邢长友,张国敏,蒋培成.基于OpenFlow的SDN技术研究[J].软件学报,2013,24(5):1078-1097. 被引量:420
  • 7Charfi Y,Wakamiya N,Murata M.Future Mobile Network Management with Attractor Selection[C]//Proceedings of the 9th Annual Conference on Wireless On-demand Network Systems and Services.Washington D.C.,USA:IEEE Press,2012:27-30.
  • 8Dan P.Trust in the Cloud:The Role of SDN[J].Network Security,2013,(3):5-6.
  • 9王硕,赵荣彩,单征.基于FSS时间序列分析的DDoS检测算法[J].计算机工程,2012,38(12):13-16. 被引量:4
  • 10Braga R,Mota E,Passito A.Lightweight DDo S Flooding Attack Detection Using NOX/Open Flow[C]//Proceedings of the 35th Conference on Local Computer Networks.Washington D.C.,USA:IEEE Press,2010:408-415.

二级参考文献94

共引文献551

同被引文献86

引证文献17

二级引证文献65

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部