首页> 外文会议>International Conference on Communication Systems and Networks >Towards resilient in-band control path routing with malicious switch detection in SDN
【24h】

Towards resilient in-band control path routing with malicious switch detection in SDN

机译:通过SDN中的恶意交换机检测实现弹性的带内控制路径路由

获取原文

摘要

In Software Defined Networks (SDNs), the control plane functionalities depend on the correctness of the information (e.g., network state) received from the data plane. A malicious switch on the in-band control path could tamper/drop the control messages, leading to misbehavior of the control plane. Hence, it is important to consider the security of in-band control paths on the southbound interface in SDN. Instead of actively probing the network with specific test packets/flows that incur high overhead on the control plane, we present in this paper, a novel control path routing approach that selects two node-disjoint control paths for every switch in the network in such a way that a malicious node can be detected based on the normal packet-in messages sent on the control paths. We develop an optimization programming formulation that provides control path routing solution and minimizes the average number of intermediate nodes while satisfying the malicious switch detection and resilience constraints. We demonstrate the effectiveness of the proposed approach through numerical analysis. The results show that the proposed approach enables faster malicious switch detection with less control overhead compared to an existing approach.
机译:在软件定义网络(SDN)中,控制平面功能取决于从数据平面接收的信息的正确性(例如,网络状态)。带内控制路径上的恶意切换可能会篡改/丢弃控制消息,从而导致控制平面的行为异常。因此,重要的是要考虑SDN中南向接口上的带内控制路径的安全性。在本文中,我们提出了一种新颖的控制路径路由方法,该方法为网络中的每个交换机选择两个节点不相交的控制路径,而不是使用在控制平面上产生高开销的特定测试数据包/流来主动探测网络。可以根据在控制路径上发送的正常打包消息来检测恶意节点的方法。我们开发了一种优化的编程公式,可以提供控制路径路由解决方案,并在满足恶意交换机检测和弹性约束的同时,最大程度地减少中间节点的平均数量。我们通过数值分析证明了该方法的有效性。结果表明,与现有方法相比,该方法可以更快地进行恶意开关检测,并且控制开销较小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号