期刊文献+

面向网络攻击态势的SDN虚拟蜜网 被引量:7

Research on SDN Virtual Honeynet for Network Attack Situation
下载PDF
导出
摘要 针对现有网络态势感知研究无法按需获取态势信息,不能根据网络攻击态势威胁情况对网络结构进行动态调整等问题,利用SDN对网络流量灵活控制的基本原理,并结合OpenDaylight控制器良好的扩展性和可管控性等性质,提出一种基于SDN的虚拟蜜网架构。通过构建SDN虚拟蜜网,实现了数据控制层与数据传输层的分离,解决了传统蜜网在网络态势获取方面存在的流量控制困难以及物理机部署不方便、动态调整部署复杂的问题。最后,利用Mininet平台搭建SDN虚拟蜜网进行仿真验证,实验结果表明SDN虚拟蜜网能够实现按需获取态势信息、动态调整网络结构等功能,从而减少网络攻击态势威胁。 Aimed at the problems that the existing network situation awareness cannot acquire on-demand situation information and cannot adjust the network structure according to situational threat of network attacks dynamically, a SDN-based virtual honeynet architecture is proposed on the basis of flexible traffic control principle with the combination of good scalability and manageability of OpenDaylight controller. Through constructing a SDN-based virtual honeynet, the separation between data control layer and data transmission layer is realized. Simultaneously, traffic controlling difficulty and inconvenience of deploying or dynamically adjusting physical machines are solved compared to traditional honeynets. At last, the paper utilizes Mininet platform for building SDN virtual honeynet. The experiment results show that the SDN-based virtual honeynet can achieve on-demand access to situation information and dynamic adjustment of network structure etc. , thus reducing the network attack threat.
出处 《空军工程大学学报(自然科学版)》 CSCD 北大核心 2017年第3期79-84,共6页 Journal of Air Force Engineering University(Natural Science Edition)
基金 陕西省工业科技攻关项目(2016GY-087)
关键词 攻击态势 软件定义网络 虚拟蜜网 按需获取 动态调整 attack situation software defined networking virtual honeynet on-demand acquisition dynamic adjustment
  • 相关文献

参考文献9

二级参考文献145

  • 1程杰仁,殷建平,刘运,钟经伟.蜜罐及蜜网技术研究进展[J].计算机研究与发展,2008,45(z1):375-378. 被引量:35
  • 2曹爱娟,刘宝旭,许榕生.网络陷阱与诱捕防御技术综述[J].计算机工程,2004,30(9):1-3. 被引量:27
  • 3陈莉,焦李成.基于关系代数的关联规则挖掘算法[J].西北大学学报(自然科学版),2005,35(6):691-694. 被引量:16
  • 4[1]T Bass.Intrusion detection systems and multi-sensor data fusion:Creating cyberspace situational awareness.Communications of the ACM,2000,43(4):99-105
  • 5[2]Xiaoxin Yin,William Yurcik,Adam Slagell.The design of VisFlowConnect-IP:A link analysis system for IP security situational awareness.The 3rd IEEE Int'l Workshop on Information Assurance (IWIA),Baltimore,USA,2005
  • 6[3]G B Stephen,S R Nageswara,S Mallikarjun.Distributed Intrusion Detection and Attack Containment for Organizational Cyber Security.http://www.ioc.ornl.gov/projects/documents/co-ntainment.pdf,2005
  • 7[4]M R Endsley.Situation awareness in aviation systems.In:D J Garland,J A Wise,V D Hopkin,eds.Handbook of Aviation Human Factors.Mahwah,NJ:Erlbaum,1999.257-276
  • 8[5]S J Kass,D A Herschler,M A Companion.Training situational awareness through pattern recognition in a battlefield environment.Military Psychology,1991,3(2):105-112
  • 9[6]R H Mogford.Mental models and situation awareness in air traffic control.The Int'l Journal of Aviation Psychology,1997,7(4):331-341
  • 10[7]Tim Bass,Dave Gruber.A glimpse into the future of id.http://www.usenix.org/publications/login/1999-9/features/future.html,2006

共引文献623

同被引文献47

引证文献7

二级引证文献31

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部