期刊文献+

基于Renyi熵的OpenFlow信道链路泛洪攻击主动防御方法 被引量:4

Active defense method of OpenFlow channel link flooding attack based on Renyi entropy
下载PDF
导出
摘要 针对新型链路泛洪攻击,提出一种基于Renyi熵的OpenFlow信道链路泛洪攻击主动防御方法。运用Renyi熵分析攻击者在构建OpenFlow信道linkmap过程中产生的ICMP超时报文数量变化。一旦出现攻击前兆,由流量监控服务器向控制器发出攻击预警,控制器启动交换机—控制器连接迁移机制,将交换机迁移至新的控制器下,并使用新的OpenFlow信道与之通信。实验证明,主动防御方法能有效避免控制器与交换机之间通信链路受到链路泛洪攻击的影响,确保控制器和交换机能持续交互提供网络服务,增强了SDN的健壮性。 For defending the new link flooding attack,this paper proposed an active defense method of OpenFlow channel link flooding based on Renyi entropy.It analyzed the changes in the number of ICMP timeout messages produced by an attacker in the construction of the OpenFlow channel linkmap from Renyi entropy.It detected once attacks precursor,flow monitoring ser- ver sent an attack warning to the controller,then controller started switch-controller connection migration mechanism,migrated the switch to a new controller and communicated with the new OpenFlow channel.Experimental results show that the active defense method can effectively avoid the impact of link flooding attack between controller and switch, and ensure that controller and switch can provide continuous network services and enhance the robustness of SDN.
作者 蔡佳晔 张红旗 宋佳良 Cai Jiaye;Zhang Hongqi;Song Jialiang(Information Engineering University,Zhengzhou 450001,China)
机构地区 信息工程大学
出处 《计算机应用研究》 CSCD 北大核心 2019年第6期1767-1770,1775,共5页 Application Research of Computers
基金 国家“863”计划资助项目(2012AA012704) 郑州市科技领军人才资助项目(131PLJRC644)
关键词 链路泛洪攻击 OpenFlow信道 RENYI熵 主动防御 link-flooding attack(LFA) OpenFlow channel Renyi entropy active defense
  • 相关文献

参考文献3

二级参考文献132

  • 1Cisco.Cisco Visual Networking Index:Forecast and Methodology,2013-2018.2013.
  • 2Stanford University.Clean slate program.2006.http://cleanslate.stanford.edu/.
  • 3McKeown N.Software-Defined metworking.In:Proc.of the INFOCOM Key Note.2009.http://infocom2009.ieee-infocom.org/ technicalProgram.htm.
  • 4McKeown N,Anderson T,Balakrishnan H,Parulkar G,Peterson L,Rexford J,Shenker S,Turner J.OpenFlow:Enabling innovation in campus networks.ACM SIGCOMM CCR,2008,38(2):69-74.[doi:10.1145/1355734.1355746].
  • 5MIT Technology Review.10 breakthrough technologies,TRIO:Software-defined networking.2009.http://www2.technology review.com/article/412194/trl0-software-defined-networking/.
  • 6Jain R.Internet 3.0:Ten problems with current Internet architecture and solutions for the next generation.In:Proc.of the IEEE MILCOM.2006.1-9.[doi:10.1109/MILCQM.2006.301995].
  • 7Nunes BAA,Mendonca M,Nguyen XN,Obraczka K,Turletti T.A survey of software-defined networking:Past,present,and future of programmable networks.IEEE Communications Surveys and Tutorials,2014,16(3):1617-1634.[doi:10.1109/SURV.2014.012214.00180].
  • 8Tennenhouse DL,Wetherall DJ.Towards an active network architecture.In:Proc.of the IEEE DARPA Active Networks Conf.and Exposition.2002.2-15.[doi:10.1109/DANCE.2002.1003480].
  • 9Tennenhouse DL,Smith JM,Sincoskie WD,Wetherall D,Minden GJ.A survey of active network research.IEEE Communications Magazine,1997,35(1):80-86.[doi:10.1109/35.568214].
  • 10Greenberg A,Hjalmtysson G,Maltz DA,Myers A5 Rexford J,Xie G,Yan Hj Zhan JBs Zhang H.A clean slate 4D approach to network control and management.ACM SIGCOMM CCR,2005,35(5):41-54.[doi:10.1145/1096536.1096541].

共引文献442

同被引文献37

引证文献4

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部