期刊文献+

SDN中基于卡方检验的DDoS防御 被引量:2

Design of DDoS attack defense system based on Chi-squared test in SDN
下载PDF
导出
摘要 针对SDN网络控制平面资源耗尽的新型DDoS攻击方式,设计并实现SDN网络环境下基于卡方检验的DDoS攻击防御系统。通过检测Packet_In消息上传加速度的异常来触发DDoS攻击检测模块;DDoS攻击检测模块收集Packet_In消息携带的信息,结合卡方检验检测DDoS攻击并筛选攻击源;根据攻击源的信息,下发应对DDoS攻击的流表,有效缓解DDoS攻击造成的网络拥塞。研究结果表明,设计的防御系统能够准确检测并有效防御DDoS攻击,对于SDN网络环境的安全保护具有重要意义。 In response to a new distributed denial of service(DDoS)attack which depletes resources in control plane,a DDoS attack defense system based on Chi-squared test was designed and implemented in software defined networks(SDN)environment.The DDoS attack detection module was triggered through detecting the abnormal upload acceleration of Packet_In messages.The information of Packet_In messages was collected through DDoS attack detection module,and the DDoS attack and the sources of the attack were detected by combining Chi-squared test.The flow entries were issued to respond DDoS attack to effectively mitigate network congestion which caused by DDoS attack.Experimental results show that the defense system is effective and accurate in detecting DDoS attacks,and it is of great significance for the protection of SDN network environment.
作者 王杨俊杰 解忧 张卫涛 WANG Yang-jun-jie;XIE You;ZHANG Wei-tao(Department of Applied Physics,College of Sciences,Xi’an University of Science and Technology,Xi’an 710054,China)
出处 《计算机工程与设计》 北大核心 2018年第9期2743-2747,共5页 Computer Engineering and Design
基金 国家自然科学基金项目(11504292) 中国博士后科学基金项目(2014M560798)
关键词 软件定义网络 OpenFlow交换机 DDOS攻击 卡方检验 Packet_In消息 software defined networks(SDN) OpenFlow switch DDoS attack Chi-squared test Packet_In message
  • 相关文献

参考文献6

二级参考文献23

  • 1McKeown N, Anderson T, Balakrishnan H, et al. OpenFlow: enabling innovation in campus networks[J]. ACM SIGCOMM Computer Communication Review, 2008,38 (2) : 69 74.
  • 2ONF Market Education Committee. Software Defined NetwoP king:The new norm for networks[EB/OL]. (2012-04-13). ht- tps://www, opennetworking, org/images/stories/downloads/ sdn resources/white-papers/wp-sdn-newnorm, pdf.
  • 3McKeown N, Anderson T, Balakrishnan H, et al. OpenFlow en- abling innovation in campus networks [J]. ACM SIOCOMM Computer Communieation Review, 2008,38(2) : 69-74.
  • 4Tootoonchian A, Gorbunov S,Ganjali Y, et al. On controller per formance in software-defined networks [C] // USENIX Work- shop on Hot Topics in Management of Internet,Cloud, and En terprise Networks and Services(Hot ICE). 2012:10.
  • 5Braga R, Mota E, Passito A. Lightweight DDoS flooding attack detection using NOX/OpenFlow[C]//2010 IEEE 35th Confer- ence on Local Computer Networks(I.CN). IEEE, 2010 : 408-415.
  • 6Wang B, Zheng Y,Lou W, et al. DDoS Attack Protection in the Era of Cloud Computing and Software-Defined Networking[C]// 2014 IEEE 22nd International Conference on Network Protocols (ICNP). IEEE, 2014 : 624-629.
  • 7Jose L, Yu M, Rexford J. Online measurement of large traffic ag- gregates on commodity switches [C]//Proc. of the USENIX HotlCE workshop. 2011 : 13-13.
  • 8Yao G, Bi J, Xiao P. Source address validation solution with OpenFlow/NOX architecture[C] // 2011 J9th IEEE International Conference on Network Protocols(ICNP). IEEE,2011:7-12.
  • 9Dover J M. A denial of service attack against the ()pen Flood light SDN controller[EB/OL]. E2013 12 301. http://dovernet- works, com/wp-content/uploads/2013/12/OpenFloodlight 1230 2013. pdf.
  • 10杨雅辉,姜电波,沈晴霓,夏敏.基于改进的GHSOM的入侵检测研究[J].通信学报,2011,32(1):121-126. 被引量:24

共引文献140

同被引文献20

引证文献2

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部