Journal on Communications ›› 2021, Vol. 42 ›› Issue (11): 41-53.doi: 10.11959/j.issn.1000-436x.2021191

• Topics: New Technology of Computer Communication and Network System Security • Previous Articles     Next Articles

Research on flood defense mechanism of SDN control layer:detection and mitigation

Qizhao ZHOU1, Junqing YU1,2, Dong LI2   

  1. 1 College of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China
    2 Center of Network and Computation, Huazhong University of Science and Technology, Wuhan 430074, China
  • Revised:2021-09-13 Online:2021-11-25 Published:2021-11-01
  • Supported by:
    The National Key Research and Development Program of China(2018YFB1800405)

Abstract:

Aiming at the problem of spoofing flood defense in the control layer of SDN, a controller defense mechanism (CDM)was proposed, including a flood detection mechanism based on key features multi-classification and a flood mitigation mechanism based on SAVI.The flood feature analysis module of the control layer was designed for flood detection, and boosting algorithm was used to overlay each feature weak classifier to form an enhanced classifier, which can achieve more accurate classification spoofing flooding attack effect by continuously reducing the residual in the calculation.In CDM, a flood mitigation mechanism based on SAVI was deployed to realize flood mitigation, which performed flood packet path filtering based on binding-verification mode, and updated the flood features of access layer switches with dynamic polling mode to reduce redundant model update load.The experimental results show that the proposed method has the characteristics of low overhead and high precision.CDM effectively increases the security of the control layer, and reduces the time of host classification of spoofing flood attack and the CPU consumption of corresponding controller.

Key words: software defined network, control layer protection, flood detection, source address validation

CLC Number: 

No Suggested Reading articles found!