针对SDN的各种攻击及缓解方法综述

Mrityunjaya D Hatagundi, H. V. Kumaraswamy
{"title":"针对SDN的各种攻击及缓解方法综述","authors":"Mrityunjaya D Hatagundi, H. V. Kumaraswamy","doi":"10.1109/ICCMC.2019.8819717","DOIUrl":null,"url":null,"abstract":"As the technologies leaning towards digitalization, there has been extensive scope for researches in the field of Software Defined Networking. The architectural framework makes the life of network administrators easy by decoupling the data plane and the control plane. This architecture exploits easy configuration of network, thus providing programmable terminal for development of applications related to security, management and logging while the centralized controller gives much more control over entire network. This type of network is at risk due to attacks by the intruders with an intention to slow down or shut down the entire network. One such kind of attacks is DoS attack. DoS attack involves flooding of fake packet flows from a single source into the original packet flow. DDoS is a type of DoS attack where multiple compromised systems, which are often infected with malicious programs, are used to target a single system. Hence to achieve security in distributed environment, it is important to reduce the effect of such attacks. In this paper an approach of mitigating Distributed DoS has been discussed. Approach first detects DDoS using Entropy Detection attack and then uses Bandwidth Prediction method to mitigate it. Entropy is basically used for measuring randomness in the system and there are two essential components to DDoS detection using entropy; window size and threshold.","PeriodicalId":232624,"journal":{"name":"2019 3rd International Conference on Computing Methodologies and Communication (ICCMC)","volume":"234 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"A Comprehensive Survey on Different Attacks on SDN and Approaches to Mitigate\",\"authors\":\"Mrityunjaya D Hatagundi, H. V. Kumaraswamy\",\"doi\":\"10.1109/ICCMC.2019.8819717\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"As the technologies leaning towards digitalization, there has been extensive scope for researches in the field of Software Defined Networking. The architectural framework makes the life of network administrators easy by decoupling the data plane and the control plane. This architecture exploits easy configuration of network, thus providing programmable terminal for development of applications related to security, management and logging while the centralized controller gives much more control over entire network. This type of network is at risk due to attacks by the intruders with an intention to slow down or shut down the entire network. One such kind of attacks is DoS attack. DoS attack involves flooding of fake packet flows from a single source into the original packet flow. DDoS is a type of DoS attack where multiple compromised systems, which are often infected with malicious programs, are used to target a single system. Hence to achieve security in distributed environment, it is important to reduce the effect of such attacks. In this paper an approach of mitigating Distributed DoS has been discussed. Approach first detects DDoS using Entropy Detection attack and then uses Bandwidth Prediction method to mitigate it. Entropy is basically used for measuring randomness in the system and there are two essential components to DDoS detection using entropy; window size and threshold.\",\"PeriodicalId\":232624,\"journal\":{\"name\":\"2019 3rd International Conference on Computing Methodologies and Communication (ICCMC)\",\"volume\":\"234 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-03-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 3rd International Conference on Computing Methodologies and Communication (ICCMC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICCMC.2019.8819717\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 3rd International Conference on Computing Methodologies and Communication (ICCMC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCMC.2019.8819717","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

摘要

随着技术向数字化的趋势发展,软件定义网络的研究已经有了广阔的空间。通过将数据平面和控制平面解耦,体系结构框架简化了网络管理员的工作。该体系结构利用了网络的简单配置,从而为开发与安全、管理和日志相关的应用程序提供了可编程终端,而集中控制器则提供了对整个网络的更多控制。这种类型的网络处于危险之中,因为入侵者的攻击意图是减慢或关闭整个网络。其中一种攻击是DoS攻击。DoS攻击是指将来自单一源的假数据包流大量注入到原始数据包流中。DDoS是DoS攻击的一种,它使用多个被感染的系统(通常被恶意程序感染)来攻击单个系统。因此,为了在分布式环境中实现安全,减少此类攻击的影响是非常重要的。本文讨论了一种减轻分布式DoS攻击的方法。该方法首先利用熵检测方法检测DDoS攻击,然后利用带宽预测方法对攻击进行缓解。熵基本上用于测量系统中的随机性,使用熵进行DDoS检测有两个基本组成部分;窗口大小和阈值。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
A Comprehensive Survey on Different Attacks on SDN and Approaches to Mitigate
As the technologies leaning towards digitalization, there has been extensive scope for researches in the field of Software Defined Networking. The architectural framework makes the life of network administrators easy by decoupling the data plane and the control plane. This architecture exploits easy configuration of network, thus providing programmable terminal for development of applications related to security, management and logging while the centralized controller gives much more control over entire network. This type of network is at risk due to attacks by the intruders with an intention to slow down or shut down the entire network. One such kind of attacks is DoS attack. DoS attack involves flooding of fake packet flows from a single source into the original packet flow. DDoS is a type of DoS attack where multiple compromised systems, which are often infected with malicious programs, are used to target a single system. Hence to achieve security in distributed environment, it is important to reduce the effect of such attacks. In this paper an approach of mitigating Distributed DoS has been discussed. Approach first detects DDoS using Entropy Detection attack and then uses Bandwidth Prediction method to mitigate it. Entropy is basically used for measuring randomness in the system and there are two essential components to DDoS detection using entropy; window size and threshold.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Review on Design & Testing of CCD Detector Data Generation & Acquisition System Comparative Analysis of Segmentation Techniques using Histopathological Images of Breast Cancer Decoding Parallel Program Execution by using Java Interactive Visualization Environment (JIVE): Behavioral and Performance Analysis Bandwidth enhancement of a rectangular inset-fed micro-strip patch antenna with DGS for ISM band Classification of Abusive Comments in Social Media using Deep Learning
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1