首页> 外国专利> NETWORK SYSTEM for FORWARDING TRAFFIC for intrusion detection ON SOFTWARE-DEFINED NETWORKS

NETWORK SYSTEM for FORWARDING TRAFFIC for intrusion detection ON SOFTWARE-DEFINED NETWORKS

机译:用于在软件定义的网络上进行入侵检测的转发流量的网络系统

摘要

The present invention relates to a traffic forwarding network system for intrusion detection in a Software Defined Network (SDN). Provided may be the network system comprising: a plurality of nodes which are connected to a network, each of which generates information to be transmitted and each of which transmits the information to another node over the network; at least one switch which is configured to transmit and receive information to and from the nodes or another switch; an SDN controller which sets a path of information in the network and which is configured to analyze information; and at least one Intrusion Detection System (IDS) which detects an intrusion into the network system through analysis of information transmitted by the SDN controller; wherein the SDN controller analyzes a plurality of data flows, i.e., paths of information between the nodes, determines similarities between the data flows, groups the data flows into a plurality of groups based on the similarities, allocates the IDS corresponding to the groups, and transmits part of information transmitted via the data flows to the IDS corresponding to the data flows. Accordingly, flows passing through similar paths in an SDN are forwarded to the identical IDS, thereby enabling an attack to be detected.
机译:本发明涉及用于软件定义网络(SDN)中的入侵检测的业务转发网络系统。可以提供一种网络系统,该网络系统包括:多个节点,其连接到网络,每个节点生成要发送的信息,并且每个节点通过网络将信息发送到另一节点。至少一个交换机,其被配置为向节点或另一交换机发送信息并从节点或另一交换机接收信息; SDN控制器,其设置网络中的信息路径并被配置为分析信息;至少一个入侵检测系统(IDS),其通过分析由SDN控制器发送的信息来检测对网络系统的入侵;其中,SDN控制器分析多个数据流,即节点之间的信息路径,确定数据流之间的相似度,根据相似度将数据流分为多个组,分配与各组相对应的IDS,将经由数据流传输的部分信息发送给与数据流相对应的IDS。因此,通过SDN中的相似路径的流被转发到相同的IDS,从而使得能够检测到攻击。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号