首页> 外文会议>IEEE Conference on Network Softwarization >Detecting and mitigating denial of service attacks against the data plane in software defined networks
【24h】

Detecting and mitigating denial of service attacks against the data plane in software defined networks

机译:在软件定义的网络中检测和缓解针对数据平面的拒绝服务攻击

获取原文

摘要

Software Defined Networking (SDN) introduces a new network architecture offering means of programmability through an externalized centralized control plane. As a result most security research addresses attacks against this central entity. Contrary to that, attacks against the data plane in SDN did not perceive a broad attention in the scientific community so far. In this work we discuss Denial of Service attacks against the data plane and their impact. We propose a tailored statistical detection approach as well as a lightweight countermeasure. We evaluate the detection by simulation and an analytical approach. Throughout this evaluation, we highlight the trade-off between detection speed and adaptability and show a way to tune the solution analytically. Our results show, that we can detect and mitigate attacks against the data plane in a lightweight and dependable way.
机译:软件定义网络(SDN)引入了一种新的网络体系结构,该体系结构通过外部化的集中控制平面提供了可编程性。结果,大多数安全性研究都针对该中央实体进行了攻击。与此相反,到目前为止,对SDN中的数据平面的攻击并未引起科学界的广泛关注。在这项工作中,我们讨论了针对数据平面的拒绝服务攻击及其影响。我们提出了量身定制的统计检测方法以及轻量级的对策。我们通过模拟和分析方法评估检测结果。在整个评估过程中,我们重点介绍了检测速度和适应性之间的权衡,并展示了一种分析解决方案的方法。我们的结果表明,我们可以以轻量级且可靠的方式检测和减轻对数据平面的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号