摘要
为保护软件定义网络(SDN)中控制器的视图安全,特别是在网络链路状态变化环境中的全局视图完整性,提出一种SDN拓扑攻击防御机制——PolicyTopo。该机制引入信息熵理论构建模型验证网络链路延时变化,同时定义数据设备端口的安全性,在防御传统拓扑攻击的同时进一步解决了网络状态变化下拓扑攻击的防御问题。在虚拟环境和物理实验台上分别布署PolicyTopo并基于Floodlight控制器进行攻防测试,结果表明,PolicyTopo能动态有效保护网络状态变化中拓扑完整性,提高网络全局视图安全性。与同类主流防御机制比较结果表明,该机制减少大量网络资源开销,增强网络安全性、灵活性以及可扩展性。
A SDN topology attack defense mechanism——PolicyTopo was proposed in order to protect the view security of the controller in software-defined networking(SDN),especially the global view integrity in the context of network link state changes.This mechanism introduces information entropy theory to build a model to verify the change of network link delay,and at the same time defines the security of data device ports.It also solves the defense problem of topology attacks under network state changes while defending against traditional topology attacks.PolicyTopo was deployed both on the virtual environment and the physical experiment platform,and the offensive and defensive tests were carried out based on Floodlight.The results show that PolicyTopo can dynamically and effectively protect the topology integrity during network state changes and improve the security of the global view of the network.Compared with other mainstream defense mechanisms,this mechanism can largely reduce the cost of network resource and improve the security,flexibility and scalability of the network.
作者
陆以勤
毛中书
程喆
覃健诚
金冬子
潘伟锵
LU Yiqin;MAO Zhongshu;CHENG Zhe;QIN Jiancheng;JIN Dongzi;PAN Weiqiang(School of Electronic and Information Engineering,South China University of Technology,Guangzhou 510640,Guangdong,China;School of Computer Science and Engineering,South China University of Technology,Guangzhou 510640,Guangdong,China;Information and Network Engineering and Research Center,South China University of Technology,Guangzhou 510640,Guangdong,China)
出处
《华南理工大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2020年第11期114-122,共9页
Journal of South China University of Technology(Natural Science Edition)
基金
广东省重点领域研发计划项目(2018B010113001,2019B010137001)
广州市科技计划项目(201902010061)。
关键词
软件定义网络
网络安全
SDN控制器
拓扑攻击
software-defined networking
cyber security
SDN controller
topology attack