一种基于SDN的自治域内恶意流量过滤机制
n SDN-based mechanism for filtering intradomain malicious traffic
自治域内部由病毒、蠕虫等原因产生的恶意流量对域内服务器、网络节点等造成严重威胁,针对传统基于边界路由器、服务器端防火墙的过滤机制在防范域内的恶意流量方面存在保护能力差、过滤规则灵活性低、部署及维护开销大等不足,提出了一种基于SDN网络的自治域内恶意流量过滤机制,从系统框架、过滤策略构建以及部署执行方面对传统流量过滤机制进行改进。首先利用SDN网络域内集中管控能力优势,设计基于Controller-Agent的过滤系统框架,通过分布式部署多个agent以观测全局统一信息并执行过滤策略, Controller则利用其计算能力实现开放式支持多种检测算法、细粒度和灵活的过滤策略制定等目标;其次设计实现基于Exception-Handler策略模型,其具备的层次化和继承特性使得过滤策略制定具备灵活性和可扩展性;最后设计实现基于过滤节点搜索的过滤策略部署执行机制,保证执行节点相对恶意流量源的近源端性、不可旁路性,最终实现恶意流量检测、策略制定与部署执行这一自反馈闭环运行流程。与传统恶意流量过滤机制相比,本文的恶意流量过滤机制在保护范围和灵活性、可扩展性上有较大优势。
Malicious traffic caused by the viruses, worms, and DDoS attack should pose a serious threat on the servers and network nodes within the AS. It is hard for traditional malicious traffic filtering mechanisms based on the edge router or end firewall to filter the malicious traffic originated from the AS self and to protect the intermediate network nodes. Their filtering policy models based on rule are inflexible and non-extensible for policy making and deploying. This paper proposed an SDN-based mechanism for filtering intradomain malicious traffic, including its system framework, policy model and filtering nodes search algorithm. Firstly, the architecture of this mechanism is based on Controller-Agent model and takes advantages of the centralized control feature of trustworthy and controllable network, and the mechanism is open for various malicious traffic detecting algorithm in support of trustworthy and controllable network's cross-layer unified information view. Secondly, this mechanism includes a filtering policies model based on Exception-Handler, and it has characteristics of hierarchy and inheritance so that the filtering policies are flexible and can be easy extended. The mechanism of this paper provides the domain more powerful, flexible and extensible capability to filter rapidly changing malicious traffic.
罗军舟、吴一娜、吴帅、李伟、陆悠
计算技术、计算机技术自动化技术、自动化技术设备
软件定义网络集中控制恶意流量过滤
Software Defined NetworkCentralized ControlMalicious Traffic Filtering
罗军舟,吴一娜,吴帅,李伟,陆悠.一种基于SDN的自治域内恶意流量过滤机制[EB/OL].(2015-01-04)[2025-08-18].http://www.paper.edu.cn/releasepaper/content/201501-6.点此复制
评论