通信学报 ›› 2022, Vol. 43 ›› Issue (3): 88-100.doi: 10.11959/j.issn.1000-436x.2022047

• 学术论文 • 上一篇    下一篇

基于地址重载的SDN分组转发验证

吴平1, 常朝稳1, 左志斌2, 马莹莹1   

  1. 1 信息工程大学密码工程学院,河南 郑州 450004
    2 河南工业大学信息科学与工程学院,河南 郑州 450001
  • 修回日期:2021-12-26 出版日期:2022-03-25 发布日期:2022-03-01
  • 作者简介:吴平(1979- ),男,安徽宿松人,信息工程大学博士生,主要研究方向为SDN安全、网络安全、数据平面编程
    常朝稳(1966- ),男,河南滑县人,博士,信息工程大学教授、博士生导师,主要研究方向为移动信息安全、物联网安全
    左志斌(1979- ),男,河南滑县人,博士,河南工业大学讲师,主要研究方向为网络安全
    马莹莹(1988- ),女,河南漯河人,信息工程大学博士生,主要研究方向为SDN安全、网络安全
  • 基金资助:
    国家自然科学基金资助项目(61572517);河南省科技攻关基金资助项目(222102210070)

Address overloading-based packet forwarding verification in SDN

Ping WU1, Chaowen CHANG1, Zhibin ZUO2, Yingying MA1   

  1. 1 Department of Cryptogram Engineering, Information Engineering University, Zhengzhou 450004, China
    2 College of Information Science and Engineering, Henan University of Technology, Zhengzhou 450001, China
  • Revised:2021-12-26 Online:2022-03-25 Published:2022-03-01
  • Supported by:
    The National Natural Science Foundation of China(61572517);Science and Technology Project of Henan Province(222102210070)

摘要:

针对软件定义网络(SDN)中现有转发验证机制大多通过加入新的安全通信协议实现分组逐跳转发验证,出现通信与计算开销的问题,提出了一种基于地址重载的 SDN 分组转发验证机制。入口交换机通过重载分组地址信息将流运行时间划分为连续随机的时间间隔,各后继节点基于重载的地址信息转发分组;控制器采样间隔内流入口与出口交换机的转发分组,检测路径中的异常转发行为;最后,构建仿真网络实现了所提机制。实验结果表明,该机制以引入不超过8%的转发延迟,可有效检测异常。

关键词: 软件定义网络, 地址重载, 哈希采样, 异常检测

Abstract:

Aiming at the problem that the most existing forwarding verification mechanisms in software-defined network (SDN) verified packets hop-by-hop by incorporating new secure communication protocols, which incurred significant computation and communication overhead, an address overloading-based forwarding verification mechanism was proposed.The flow runtime was divided into consecutive random intervals by the ingress switch via overloading address fields of packet, basing on overloading address, packets were forwarded by each subsequent switch, and the controller sampled the packets forwarded by ingress and egress switch in the interval to detect abnormal behavior on the path.Finally, the proposed mechanism and simulation network was implemented and evaluated.Experiments show that the mechanism achieves efficient forwarding and effective anomaly detection with less than 8% of additional forwarding delays.

Key words: software-defined networking, address overloading, hash-based sampling, anomaly detection

中图分类号: 

No Suggested Reading articles found!