Chinese Journal of Network and Information Security ›› 2021, Vol. 7 ›› Issue (3): 85-94.doi: 10.11959/j.issn.2096-109x.2021049

• TopicⅡ: SDN and cloud computing security • Previous Articles     Next Articles

SDN self-protection system based on Renyi entropy

Pu ZHAO1, Wentao ZHAO1, Zhangjie FU2, Qiang LIU1   

  1. 1 College of Computer, National University of Defense Technology, Changsha 410073, China
    2 School of Computer &Software, Nanjing University of Information Science &Technology, Nanjing 210044, China
  • Revised:2020-11-16 Online:2021-06-15 Published:2021-06-01
  • Supported by:
    The National Natural Science Foundation of China(U1811462);The National Natural Science Foundation of China(61702539);The Natural Science Foundation of Hunan Province(2018JJ3611)

Abstract:

Aiming at the abnormal behaviors in SDN architecture, a self-protection system based on Renyi entropy that implemented a set of detection, diagnosis and defense method of SDN abnormal behaviors was proposed.The system did not need to introduce the third-party measurement equipment, and directly used the flow table information of OpenFlow switches.Firstly, the abnormal network behavior was detected by calculating the characteristic entropy.Then, the information of the OpenFlow flow table was further analyzed to realize the diagnosis of abnormal behavior.Finally, a blacklist mechanism was established.And the system added the hosts with abnormal behavior to the blacklist and blocked the corresponding abnormal traffic.In order to verify the effectiveness of the system, a prototype was developed on the Floodlight controller.The simulation results on Mininet show that the system can effectively detect, diagnose and defend the abnormal behaviors.The system has low deployment cost, which enhances the security of SDN.

Key words: software defined network, anomaly detection, Renyi entropy, OpenFlow protocol

CLC Number: 

No Suggested Reading articles found!