期刊文献+

软件定义网络抗拒绝服务攻击的流表溢出防护 被引量:2

Preventing flow table overflow against denial of service attack in software defined network
下载PDF
导出
摘要 针对拒绝服务攻击导致软件定义网络交换机有限的流表空间溢出、正常的网络报文无法被安装流表规则、报文转发时延、丢包等情况,提出了抗拒绝服务攻击的软件定义网络流表溢出防护技术FloodMitigation,采用基于流表可用空间的限速流规则安装管理,限制出现拒绝服务攻击的交换机端口的流规则最大安装速度和占用的流表空间数量,避免了流表溢出。此外,采用基于可用流表空间的路径选择,在多条转发路径的交换机间均衡流表利用率,避免转发网络报文过程中出现网络新流汇聚导致的再次拒绝服务攻击。实验结果表明,FloodMitigation在防止交换机流表溢出、避免网络报文丢失、降低控制器资源消耗、确保网络报文转发时延等方面能够有效地缓解拒绝服务攻击的危害。 Aiming at denial of service attacks would cause overflow of the limited flow table space of the switch in software defined network,failure to install flow table rules for normal network packets,packet forwarding delay,and packet loss,FloodMitigation was proposed to prevent flow table overflow against denial of service attacks in software defined network.The management of the rate-limit flow rule installation based on available flow table space was adopted to limit the maximum installation speed of flow rules and the number of flow table space occupied by switch ports with denial-of-service attacks,and avoid flow table overflow.In addition,path selection based on available flow table space was adopted to balance flow table utilization of switches among multiple forwarding paths to avoid denial of service attacks on switches with less available flow table in the path.The experimental results demonstrate that FloodMitigation can effectively alleviate the harm of denial of service attacks in terms of preventing switch flow table overflow and packet loss,reducing resource consumption of controllers,and ensuring packet forwarding delay.
作者 王东滨 吴东哲 智慧 郭昆 张勖 时金桥 张宇 陆月明 WANG Dongbin;WU Dongzhe;ZHI Hui;GUO Kun;ZHANG Xu;SHI Jinqiao;ZHANG Yu;LU Yueming(School of Cyberspace Engineering,Beijing University of Posts and Telecommunications,Beijing 100876,China;Engineering Research Center of Blockchain and Network Convergence Technology,Ministry of Education,Beijing 100876,China;TravelSky Technology Limited,Beijing 100190,China;National Engineering Research Center for Mobile Network,Beijing 100876,China;Zhongguancun Laboratory,Beijing 100094,China;School of Cyberspace Science,Harbin Institute of Technology,Harbin 150001,China;Cyberspace Security Research Center,Peng Cheng Laboratory,Shenzhen 518055,China)
出处 《通信学报》 EI CSCD 北大核心 2023年第2期1-11,共11页 Journal on Communications
基金 国家重点研发计划基金资助项目(No.2020YFB1808100) 中国高校产学研创新基金资助项目(No.2021FNA02004)。
关键词 软件定义网络 拒绝服务攻击 流表溢出 路径选择 software defined network denial of service attack flow table overflow path selection
  • 相关文献

参考文献2

二级参考文献123

  • 1Cisco.Cisco Visual Networking Index:Forecast and Methodology,2013-2018.2013.
  • 2Stanford University.Clean slate program.2006.http://cleanslate.stanford.edu/.
  • 3McKeown N.Software-Defined metworking.In:Proc.of the INFOCOM Key Note.2009.http://infocom2009.ieee-infocom.org/ technicalProgram.htm.
  • 4McKeown N,Anderson T,Balakrishnan H,Parulkar G,Peterson L,Rexford J,Shenker S,Turner J.OpenFlow:Enabling innovation in campus networks.ACM SIGCOMM CCR,2008,38(2):69-74.[doi:10.1145/1355734.1355746].
  • 5MIT Technology Review.10 breakthrough technologies,TRIO:Software-defined networking.2009.http://www2.technology review.com/article/412194/trl0-software-defined-networking/.
  • 6Jain R.Internet 3.0:Ten problems with current Internet architecture and solutions for the next generation.In:Proc.of the IEEE MILCOM.2006.1-9.[doi:10.1109/MILCQM.2006.301995].
  • 7Nunes BAA,Mendonca M,Nguyen XN,Obraczka K,Turletti T.A survey of software-defined networking:Past,present,and future of programmable networks.IEEE Communications Surveys and Tutorials,2014,16(3):1617-1634.[doi:10.1109/SURV.2014.012214.00180].
  • 8Tennenhouse DL,Wetherall DJ.Towards an active network architecture.In:Proc.of the IEEE DARPA Active Networks Conf.and Exposition.2002.2-15.[doi:10.1109/DANCE.2002.1003480].
  • 9Tennenhouse DL,Smith JM,Sincoskie WD,Wetherall D,Minden GJ.A survey of active network research.IEEE Communications Magazine,1997,35(1):80-86.[doi:10.1109/35.568214].
  • 10Greenberg A,Hjalmtysson G,Maltz DA,Myers A5 Rexford J,Xie G,Yan Hj Zhan JBs Zhang H.A clean slate 4D approach to network control and management.ACM SIGCOMM CCR,2005,35(5):41-54.[doi:10.1145/1096536.1096541].

共引文献502

同被引文献8

引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部