期刊文献+

基于软件定义网络的DDoS攻击检测方案 被引量:3

DDoS attack detection scheme based on software-defined networking
下载PDF
导出
摘要 分布式拒绝服务(distributed denial-of-service,DDoS)攻击是网络中的常见威胁,攻击者通过向受害服务器发送大量无用请求使正常用户无法访问服务器,DDoS逐渐成为软件定义网络(software-defined networking,SDN)的重大安全隐患。针对SDN中DDoS攻击检测问题,提出了一种粗粒度与细粒度相结合的检测方案,使用队列论及条件熵作为到达流的粗粒度检测模块,使用机器学习作为细粒度检测模块,从合法包中准确检测出恶意流量。实验表明,在使用Mininet模拟SDN网络的环境中,方案可准确检测出DDoS攻击。 Distributed denial-of-service(DDoS)attacks are a common threat in many networks.Attackers send a large number of useless requests to the victim server to prevent other users from accessing the server.These attacks rely on a high degree of randomness to establish a large number of connections with victims,which makes it difficult to be detected and blocked by the firewall.With the rapid development of software defined networking(SDN),DDoS attacks have gradually become a major concern in SDN.For the problem of DDoS attack detection in SDN,a combined coarse-grained and fine-grained attack detection scheme is proposed,using queueing theory and conditional entropy as the coarse-grained detection module for arriving flows and machine learning as the fine-grained detection module to accurately detect malicious traffic from legitimate packets.Experiments show that the detection scheme can accurately and efficiently detect DDoS attacks in a simulated SDN network environment using Mininet.
作者 谢汶锦 张智斌 张三妞 XIE Wenjin;ZHANG Zhibin;ZHANG Sanniu(Faculty of Information Engineering and Automation,Kunming University of Science and Technology,Kunming 650500,P.R.China)
出处 《重庆邮电大学学报(自然科学版)》 CSCD 北大核心 2022年第6期1032-1039,共8页 Journal of Chongqing University of Posts and Telecommunications(Natural Science Edition)
关键词 软件定义网络 分布式拒绝服务攻击 条件熵 队列论 机器学习 software-defined networking distributed denial-of-service attack conditional entropy queueing theory machine learning
  • 相关文献

参考文献6

二级参考文献135

  • 1穆祥昆,王劲松,薛羽丰,黄玮.基于活跃熵的网络异常流量检测方法[J].通信学报,2013,34(S2):51-57. 被引量:20
  • 2孙知信,姜举良,焦琳.DDOS攻击检测和防御模型[J].软件学报,2007,18(9):2245-2258. 被引量:34
  • 3Cisco.Cisco Visual Networking Index:Forecast and Methodology,2013-2018.2013.
  • 4Stanford University.Clean slate program.2006.http://cleanslate.stanford.edu/.
  • 5McKeown N.Software-Defined metworking.In:Proc.of the INFOCOM Key Note.2009.http://infocom2009.ieee-infocom.org/ technicalProgram.htm.
  • 6McKeown N,Anderson T,Balakrishnan H,Parulkar G,Peterson L,Rexford J,Shenker S,Turner J.OpenFlow:Enabling innovation in campus networks.ACM SIGCOMM CCR,2008,38(2):69-74.[doi:10.1145/1355734.1355746].
  • 7MIT Technology Review.10 breakthrough technologies,TRIO:Software-defined networking.2009.http://www2.technology review.com/article/412194/trl0-software-defined-networking/.
  • 8Jain R.Internet 3.0:Ten problems with current Internet architecture and solutions for the next generation.In:Proc.of the IEEE MILCOM.2006.1-9.[doi:10.1109/MILCQM.2006.301995].
  • 9Nunes BAA,Mendonca M,Nguyen XN,Obraczka K,Turletti T.A survey of software-defined networking:Past,present,and future of programmable networks.IEEE Communications Surveys and Tutorials,2014,16(3):1617-1634.[doi:10.1109/SURV.2014.012214.00180].
  • 10Tennenhouse DL,Wetherall DJ.Towards an active network architecture.In:Proc.of the IEEE DARPA Active Networks Conf.and Exposition.2002.2-15.[doi:10.1109/DANCE.2002.1003480].

共引文献478

同被引文献36

引证文献3

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部