通信学报 ›› 2021, Vol. 42 ›› Issue (11): 41-53.doi: 10.11959/j.issn.1000-436x.2021191

• 专题:计算机通信与网络系统安全技术 • 上一篇    下一篇

SDN控制层泛洪防御机制研究:检测与缓解

周启钊1, 于俊清1,2, 李冬2   

  1. 1 华中科技大学计算机学院,湖北 武汉 430074
    2 华中科技大学网络与计算中心,湖北 武汉 430074
  • 修回日期:2021-09-13 出版日期:2021-11-25 发布日期:2021-11-01
  • 作者简介:周启钊(1991− ),男,湖南长沙人,华中科技大学博士生,主要研究方向为机器学习、软件定义网络、网络安全等
    于俊清(1975− ),男,内蒙古赤峰人,博士,华中科技大学教授、博士生导师,主要研究方向为数字媒体处理与检索、网络安全、多核计算与流编译等
    李冬(1979− ),男,湖北武汉人,博士,华中科技大学讲师,主要研究方向为网络安全、入侵检测、僵尸网络检测、网络流数据挖掘与分析、无线网络跨层优化等
  • 基金资助:
    国家重点研发计划基金资助项目(2018YFB1800405)

Research on flood defense mechanism of SDN control layer:detection and mitigation

Qizhao ZHOU1, Junqing YU1,2, Dong LI2   

  1. 1 College of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China
    2 Center of Network and Computation, Huazhong University of Science and Technology, Wuhan 430074, China
  • Revised:2021-09-13 Online:2021-11-25 Published:2021-11-01
  • Supported by:
    The National Key Research and Development Program of China(2018YFB1800405)

摘要:

针对SDN控制层中的欺骗式泛洪防御问题,提出控制器防御机制(CDM),主要包括基于关键特征多分类的泛洪检测机制和基于SAVI的泛洪缓解机制2个方面。在泛洪检测方面提出控制层泛洪关键特征解析模块,利用Boosting算法将各个关键特征弱分类器加权叠加形成增强型分类器,通过不断降低计算中的残差,达到更准确分类针对控制层的欺骗式泛洪攻击的效果。在泛洪缓解方面,CDM部署基于SAVI的泛洪缓解机制,以绑定和验证的模式为基础执行泛洪数据包的路径过滤,同时以动态轮询的模式实现泛洪攻击安全保障和接入层交换机泛洪关键特征数据的更新,降低冗余的模型更新负载。实验结果表明,所提方法具备开销低、精度高的特点,有效地增加了控制层的安全性,减少了欺骗式泛洪攻击主机分类的时间和对应控制器CPU的消耗。

关键词: 软件定义网络, 控制层防护, 泛洪检测, 源地址验证

Abstract:

Aiming at the problem of spoofing flood defense in the control layer of SDN, a controller defense mechanism (CDM)was proposed, including a flood detection mechanism based on key features multi-classification and a flood mitigation mechanism based on SAVI.The flood feature analysis module of the control layer was designed for flood detection, and boosting algorithm was used to overlay each feature weak classifier to form an enhanced classifier, which can achieve more accurate classification spoofing flooding attack effect by continuously reducing the residual in the calculation.In CDM, a flood mitigation mechanism based on SAVI was deployed to realize flood mitigation, which performed flood packet path filtering based on binding-verification mode, and updated the flood features of access layer switches with dynamic polling mode to reduce redundant model update load.The experimental results show that the proposed method has the characteristics of low overhead and high precision.CDM effectively increases the security of the control layer, and reduces the time of host classification of spoofing flood attack and the CPU consumption of corresponding controller.

Key words: software defined network, control layer protection, flood detection, source address validation

中图分类号: 

No Suggested Reading articles found!