期刊文献+
共找到1篇文章
< 1 >
每页显示 20 50 100
Defense Against Software-Defined Network Topology Poisoning Attacks 被引量:1
1
作者 Yang Gao Mingdi Xu 《Tsinghua Science and Technology》 SCIE EI CAS CSCD 2023年第1期39-46,共8页
Software-Defined Network(SDN)represents a new network paradigm.Unlike conventional networks,SDNs separate control planes and data planes.The function of a data plane is enabled using switches,whereas that of a control... Software-Defined Network(SDN)represents a new network paradigm.Unlike conventional networks,SDNs separate control planes and data planes.The function of a data plane is enabled using switches,whereas that of a control plane is facilitated by a controller.The controller learns network topologies and makes traffic forwarding decisions.However,some serious vulnerabilities are gradually exposed in the topology management services of current SDN controller designs.These vulnerabilities mainly exist in host tracking and link discovery services.Attackers can exploit these weak points to poison the network topology information in SDN controllers.In this study,a novel solution is proposed to defend against topology poisoning attacks.By analyzing the existing topology attack principles and threat models,this work constructs legal conditions for host migration to detect host hijacking attacks.The checking of the Link Layer Discovery Protocol(LLDP)source and integrity is designed to defend against link fabrication attacks.A relay-type link fabrication attack detection method based on entropy is also designed.Results show that the proposed solution can effectively detect existing topological attacks and provide complete and comprehensive topological security protection. 展开更多
关键词 Software-Defined Network(SDN) topology discovery topology poisoning attacks
原文传递
上一页 1 下一页 到第
使用帮助 返回顶部