期刊文献+

基于端口跳变的SDN网络防御技术 被引量:7

Port hopping based SDN network defense technology
下载PDF
导出
摘要 端口跳变是移动目标防御典型技术,通过持续改变服务端口来隐藏服务标志和迷惑攻击者。利用SDN逻辑集中控制与网络可编程特性,提出基于端口跳变的SDN网络防御技术。使用SDN控制器承担服务端的端口跳变功能,不但可以减轻服务端负载,而且能提前检测过滤恶意数据包,并能抵御内部攻击者。理论分析与实验结果表明,所提技术对SDN控制器负载增加较少,可有效抵御Do S攻击。 Port hopping was a typical technology of m oving target defense, which constantly changed service port number to hide service identifications and confused potential attackers. Using SDN logically centralized control and network program mable features, this paper proposed a po rt hopping based SDN netw ork defense tech nolog y, which utilized SDN controlle r to im plement port hopping function . This proposed technology not on ly cou ld reduce protected server5 s load caused by port hoppin g , but also could detect and early filte r m a licio us packets. At the same tim e , i t cou ld defend against in te rn a l attackers.T h eoretical analysis and experim ental results show th a t this proposed technology can effectively resist DoS attack w ith o u t addingm uch load on SDN c o n tro lle r in SDN.
作者 唐秀存 张连成 史晓敏 徐良华 Tang Xiucun;Zhang Liancheng;Shi Xiaomin;Xu Lianghua(Jiangnan Institute of Computing Technology, Wuxi Jiangsu 214083 , China;State Key Laboratory of Mathematical Engineering & Advanced Computing, Zhengzhou 450001 , China)
出处 《计算机应用研究》 CSCD 北大核心 2016年第10期3083-3087,共5页 Application Research of Computers
基金 国家青年自然科学基金资助项目(61402525 61402526) 国家"863"计划资助项目(2012AA012902)
关键词 软件定义网络 拒绝服务攻击 端口跳变 移动目标防御 控制器 时间戳反馈 software defined network denial of service attack port hopping moving target defense controller timestamp feedback
  • 相关文献

参考文献4

二级参考文献189

  • 1贾春福,林楷,鲁凯.基于端信息跳变DoS攻击防护机制中的插件策略[J].通信学报,2009,30(S1):114-118. 被引量:10
  • 2马祺,戴浩,赵新昱,赵鹏.运用跳端口技术进行信息隐藏[J].计算机工程与设计,2007,28(4):849-851. 被引量:20
  • 3Mckeown N, Anderson T, Balakrishnan H, Parulkar G, Peterson L, Rexford J, Shenker S, Turner J. OpenFlow: Enabling innovation in campus networks. ACM SIGCOMM Computer Communication Review, 2008,38(2):69-74. [doi: 10.1145/1355734. 1355746].
  • 4Elliott C. GENI: Opening up new classes of experiments in global networking. IEEE Internet Computing, 2010,14(1):39-42.
  • 5Gavras A, Karila A, Fdida S, May M, Potts M. Future Internet research and experimentation: The FIRE initiative. ACM SIGCOMM Computer Communication Review, 2007,37(3):89-92. [doi: 10.114511273445.1273460].
  • 6JGN2plus. 2012. http://www.jgn.nict.go.jp/english/index.html.
  • 7SOFIA. 2012. http://fi.ict.ac.cn/research/sofia_overview.htm.
  • 8Yang L, Dantu R, Anderson T, Gopal R. Forwarding and Control Element Separation (ForCES) Framework. RFC 3746, 2004. http://tools.ietf.org/html/rfc3746.
  • 9Greenberg A, Hjalmtysson G, Maltz DA, Myers A, Rexford J, Xie G, Yan H, Zhan J, Zhang H. A clean slate 4D approach to network control and management. ACM SIGCOMM Computer Communication Review, 2005,35(5):41-54. [doi: 10.1145/1096536. 1096541].
  • 10Caesar M, Caldwell D, Feamster N, Rexford J, Shaikh A, Merwe J. Design and implementation of a routing control platform. In: Proc. of the 2rd USENIX Symp. on Networked Systems Design and Implementation (NSDI). Boston: USENIX Association, 2005. 15-28.

共引文献778

同被引文献48

引证文献7

二级引证文献20

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部