基于信誉的软件定义网络饱和攻击缓解策略
Mitigation of Saturation Attack Based on Reputation in SDN
软件定义网络(Software-Defined Networking,SDN)中,饱和攻击利用其集中式架构制造大量不匹配的packet-in数据包消耗中央控制器的资源,从而影响网络服务质量,甚至令控制器过载造成网络崩溃。本文针对以上问题提出了基于信誉值的缓解策略,为交换机端口节点定义信誉值,并通过信誉值分配控制器的可请求资源。在检测阶段,根据端口的流量特征将端口分为正常,可疑与攻击三类。缓解阶段根据检测的结果,首先过滤攻击流量,对于正常端口提高信誉值,可疑端口降低信誉值,并实现基于信誉值的限流模型。最后在软件环境中进行了模拟实验,结果表明我们的系统可以有效地减轻控制器的CPU和内存压力。
In software defined Networking (SDN), saturation attack uses its centralized architecture to produce a large number of mismatched packets, which consumes the resources of the central controller, thus affecting the quality of service of the network and even overloading the controller, resulting in network collapse. Aiming at the above problems, this paper proposes a mitigation strategy based on reputation value, defines the reputation value for the switch port node, and allocates the requested resources of the controller through the reputation value. The detection of suspicious ports is divided into three stages according to the characteristics of suspicious ports and normal ports. In the mitigation stage, according to the detection results, firReearch of mitigation of saturation attack in software defined networkingstly filter the attack traffic, increase the reputation value for the normal port, reduce the reputation value for the suspicious port, and realize the flow restriction model based on the reputation valuResearch on mitigation of saturation attack based on reputation in SDNe. Finally, the simulation experiment is carried out in the software environment, we demonstrate the effectiveness with the experiment in an SDN testbed. Also, results showed that our system can efficiently relieve CPU and memory pressure of controller with negligible overhead.
赵玉洁、王东滨
通信
计算机软件软件定义网络饱和攻击信誉值
omputer SoftwareSoftware-Defined NetworkingSaturation AttackReputation
赵玉洁,王东滨.基于信誉的软件定义网络饱和攻击缓解策略[EB/OL].(2022-03-10)[2025-08-11].http://www.paper.edu.cn/releasepaper/content/202203-109.点此复制
评论