Journal on Communications ›› 2017, Vol. 38 ›› Issue (10): 102-112.doi: 10.11959/j.issn.1000-436x.2017202

• Papers • Previous Articles     Next Articles

Moving target defense solution on network layer based on OpenFlow

Yi-xun HU1,Kang-feng ZHENG1,Yi-xian YANG1,2,Xin-xin NIU1,2   

  1. 1 College of Cyberspace Security,Beijing University of Posts and Telecommunications,Beijing 100876,China
    2 State Key Laboratory of Public Big Data,Guizhou University,Guiyang 550025,China
  • Revised:2017-07-08 Online:2017-10-01 Published:2017-11-16
  • Supported by:
    The National Key Research and Development Program of China(2017YFB0802703);The National Natural Science Foundation of China(61602052)

Abstract:

In order to take an active part in network attack and defense,a moving target defense solution on network layer based on OpenFlow was proposed,using the flexibility of network brought by OpenFlow network architecture.On the network layer,through mapping the correspondent nodes’ addresses to pseudo-random virtual addresses in the LAN and mapping correspondent nodes’ ports to virtual ports,achieving the hiding of correspond nodes in the whole network and the information of network architecture.Researches verify the system’s effectiveness.Comparing with existing moving target defense solutions,the proposed algorithm can be deployed easily in the traditional network,and realize comprehensive protection of the corresponding in the whole network.

Key words: active defense, OpenFlow, moving target defense

CLC Number: 

No Suggested Reading articles found!