网络与信息安全学报 ›› 2021, Vol. 7 ›› Issue (3): 85-94.doi: 10.11959/j.issn.2096-109x.2021049

• 专栏Ⅱ:SDN与云计算安全 • 上一篇    下一篇

基于Renyi熵的SDN自主防护系统

赵普1, 赵文涛1, 付章杰2, 刘强1   

  1. 1 国防科技大学计算机学院,湖南 长沙 410073
    2 南京信息工程大学计算机与软件学院,江苏 南京 210044
  • 修回日期:2020-11-16 出版日期:2021-06-15 发布日期:2021-06-01
  • 作者简介:赵普(1991- ),男,河南安阳人,国防科技大学硕士生,主要研究方向为软件定义网络安全
    赵文涛(1978- ),男,博士,内蒙古凉城人,国防科技大学教授、博士生导师,主要研究方向为网络性能优化、信息处理和机器学习
    付章杰(1983- ),男,博士,河南南阳人,南京信息工程大学教授、博士生导师,主要研究方向为网络与信息安全等
    刘强(1986- ),男,博士,江西临川人,国防科技大学副教授,主要研究方向为网络安全和机器学习
  • 基金资助:
    国家自然科学基金(U1811462);国家自然科学基金(61702539);湖南省自然科学基金(2018JJ3611)

SDN self-protection system based on Renyi entropy

Pu ZHAO1, Wentao ZHAO1, Zhangjie FU2, Qiang LIU1   

  1. 1 College of Computer, National University of Defense Technology, Changsha 410073, China
    2 School of Computer &Software, Nanjing University of Information Science &Technology, Nanjing 210044, China
  • Revised:2020-11-16 Online:2021-06-15 Published:2021-06-01
  • Supported by:
    The National Natural Science Foundation of China(U1811462);The National Natural Science Foundation of China(61702539);The Natural Science Foundation of Hunan Province(2018JJ3611)

摘要:

针对SDN架构下的常见网络异常行为,提出了一套基于Renyi熵的SDN自主防护系统,该系统可实现网络异常行为检测、诊断及防御。系统无须引入第三方测量设备,直接利用OpenFlow交换机流表信息。首先,通过计算和检测特征熵值,实现异常网络行为的检测。然后,进一步分析OpenFlow流表信息,实现异常行为的诊断。最后,实施防御控制措施,建立一套黑名单机制,将产生异常行为的主机加入黑名单,并阻塞相应的异常流量。为了验证系统的有效性,在Floodlight控制器上开发了原型。Mininet上的仿真实验表明,系统能够有效检测、诊断及防御网络中常见的异常行为,且具有较低的部署成本,增强了SDN的安全性。

关键词: 软件定义网络, 网络异常检测, Renyi熵, OpenFlow协议

Abstract:

Aiming at the abnormal behaviors in SDN architecture, a self-protection system based on Renyi entropy that implemented a set of detection, diagnosis and defense method of SDN abnormal behaviors was proposed.The system did not need to introduce the third-party measurement equipment, and directly used the flow table information of OpenFlow switches.Firstly, the abnormal network behavior was detected by calculating the characteristic entropy.Then, the information of the OpenFlow flow table was further analyzed to realize the diagnosis of abnormal behavior.Finally, a blacklist mechanism was established.And the system added the hosts with abnormal behavior to the blacklist and blocked the corresponding abnormal traffic.In order to verify the effectiveness of the system, a prototype was developed on the Floodlight controller.The simulation results on Mininet show that the system can effectively detect, diagnose and defend the abnormal behaviors.The system has low deployment cost, which enhances the security of SDN.

Key words: software defined network, anomaly detection, Renyi entropy, OpenFlow protocol

中图分类号: 

No Suggested Reading articles found!