期刊文献+

基于SDN的分布式欺骗防御系统 被引量:2

Distributed deception defense system based on SDN
下载PDF
导出
摘要 软件定义网络(SDN)通过分离数据与控制平台为网络提供高度开放性和可编程性。针对已有工作中SDN主动防御框架缺乏考虑网络瓶颈的问题,提出了基于SDN的分布式欺骗防御系统DDS。首先,使用多层划分算法根据物理网络的设备属性将其划分为不同区域。在此基础上为每个区域设计不同欺骗拓扑和针对攻击方侦查行为的欺骗策略,在攻击方已经成功入侵网络,但潜伏的主机位置不明的假设下,系统内的各个区域按照相应欺骗拓扑和策略执行欺骗任务。实验表明该系统能够有效干扰侦查行为,为防御方争取时间,而且区域划分将节点数量为10 000个的网络划分成3个区域时仅需11.9 ms。 By separating the control plane from the data plane,Software-Defined Network(SDN)empowers the network operators with more flexibility to program their network.However,the existing SDN active defense solutions lacks the consideration of network bottlenecks.A distributed deceptive defense system based on SDN(DDS)was developed to solve the problem.The multilevel graph partitioning scheme was introduced to divide the network into different regions according to its device properties.The deception topologies and policies for each region to thwart network reconnaissance were designed,which base on the assumption that the attacker has successfully invade the network hosts with its location unknown.The results of test show that DDS is able to interfere with the adversarial reconnaissance effectively and buy more time for defenders,while topology division only takes11.9ms when dividing a network with10000nodes.
作者 徐明迪 高杨 崔峰 XU Mingdi;GAO Yang;CUI Feng(Wuhan Digital Engineering Institute, Wuhan 430205, China)
出处 《通信学报》 EI CSCD 北大核心 2018年第A02期54-60,共7页 Journal on Communications
关键词 软件定义网络 欺骗技术 主动安全防御 网络攻防 SDN deception active security defense network attack and defense
  • 相关文献

参考文献3

二级参考文献30

  • 1程杰仁,殷建平,刘运,钟经伟.蜜罐及蜜网技术研究进展[J].计算机研究与发展,2008,45(z1):375-378. 被引量:35
  • 2曹爱娟,刘宝旭,许榕生.网络陷阱与诱捕防御技术综述[J].计算机工程,2004,30(9):1-3. 被引量:27
  • 3Wen Xitao, Chen Yan, Hu Chengchen, Shi Chao. Towards a secure controller platform for OpenFlow applications//Proceedings of the ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking (HotSDN13). Hong Kong, China, 2013:171-172.
  • 4Kreutz D, Ramos F, Verissimo P. Towards secure and dependable software-defined networks//Proceedings of the ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking (HotSDN13). Hong Kong, China, 2013:55-60.
  • 5Kazemian P, Varghese G, McKeown N. Header space analysis: Static checking for networks//Proceedings of the 9th USENIX Symposium on Network Systems Design and Imple- mentation (NSDI). San Jose, USA, 2012:3-5.
  • 6Kazemian P, Chang M, Zeng Hongyi. Real time network policy checking using header space analysis//Proceedings of the 9th USENIX Symposium on Network Systems Design and Implementation (NSDI). Lombard, USA, 2013.. 4-6.
  • 7Porras P, Shin S, Yegneswaran V, Fong M. A security enforcement kernel for OpenFlow networks//Proceedings of the ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking (HotSDN2012). New York, USA, 2012:123-125.
  • 8Sherwood R, Gibb G, Yap K K, et al. FlowVisor: A network virtualization layer. OpenFlow Switch Consortium, CA, USA: OPENFLOW-TR-2009-1, 2009.
  • 9Son S, Shin S, Yegneswaran V, Porras P. Model checking invariant security properties in OpenF|ow//Vroceedings of the IEEE International Conference on Communications (ICC' 2013). Budapest, Hungary, 2013:2-6.
  • 10Monsanto C, Reich J, Foster N, Rexford J, Walker D. Composing software defined networks//Proceedings of the 10th USENIX Conference on Networked Systems Design and Implementation. Berkeley, USA, 2013:1-14.

共引文献113

同被引文献28

引证文献2

二级引证文献6

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部