软件定义网络中的分布式拒绝服务攻击抑制模型
闫 巧, 龚庆祥, 于 非

深圳大学计算机与软件学院,广东深圳 518060

通信系统; 软件定义网络; OpenFlow协议; 分布式拒绝服务攻击; 模糊综合评判决策模型

The inhibition model of DDoS attacks in SDN networks
Yan Qiao, Gong Qingxiang, and Yu Fei

Yan Qiao, Gong Qingxiang, and Yu FeiCollege of Computer Science and Software Engineering, Shenzhen University, Shenzhen 518060, Guangdong Province, P.R.China

communication system; software defined networking; OpenFlow protocol; distributed denial of service attack attacks; fuzzy synthetic evaluation decision-making model

DOI: 10.3724/SP.J.1249.2017.06562

备注

针对软件定义网络(software defined networking, SDN)中控制器受到分布式拒绝服务(distributed denial of service, DDoS)攻击致使SDN网络可能面临单点失效的威胁,提出抑制SDN网络中DDoS攻击的模型.该模型主要是在SDN应用层上扩展DDoS检测模块和MSlot(multiple timeslot)算法模块.在DDoS攻击检测上,DDoS检测模块采用模糊综合评判决策模型,通过综合多个流特征指标实时检测DDoS的发生,并使用DDoS综合评判分数描述DDoS攻击的强度.在应对DDoS攻击流策略上,MSlot算法模块根据检测结果采取相应的时间片分配策略,确保SDN网络在DDoS攻击下可有效保护合法用户的通信.为测试DDoS抑制模型,通过仿真模拟不同攻击强度的DDoS攻击.结果表明,在SDN网络中,相比某些基于单因素评判指标的DDoS攻击检测算法,采用模糊综合评判决策模型在检测率和精确度上更有优势; 在DDoS攻击时,MSlot算法模块根据检测结果采取相应的时间片分配策略相比某些只使用多个逻辑队列轮询机制的SDN控制器调度算法可更有效地保护合法用户的通信质量.

In software defined networking(SDN), the controller may suffer from distributed denial of service(DDoS)attack, which may cause the threat of single point of failure. In this paper, a model is proposed to defend against DDoS attacks in SDN. In the model, DDoS detection module and multiple timeslot(MSlot)algorithm module are extended in the application layer. For DDoS attack detection, DDoS detection module is based on fuzzy synthetic evaluation decision-making model. It can detect the occurrence of DDoS in real time according to the multiple flow characteristic indexes and use the DDoS comprehensive evaluation scores to describe the strength of DDoS attack. For the strategy of defeating DDoS attacks, MSlot algorithm module is designed to decide when applying the time slice allocation strategy to get the detection result from DDoS detection module. The strategy can effectively protect the communication of legitimate users under the DDoS attacks. In order to test the model, we simulate DDoS attacks with different intensities. The results from different intensities of DDoS attacks show that in SDN networks, compared with some other DDoS attacks detection algorithms based on single flow characteristic index, ‘DDoS detection module' has better detection rate and accuracy by using the fuzzy comprehensive evaluation decision model. Compared with some other SDN controller scheduling algorithms which only use multiple logical queue and polling mechanism, the communication quality of legitimate users can be protected more effectively by MSlot algorithm module.

深圳SEO优化公司福州网站关键词优化价格黑河SEO按天收费林芝品牌网站设计推荐醴陵设计公司网站推荐北海网站建设价格白山网站seo优化公司广元百度网站优化排名推荐安阳建站报价凉山网站seo优化推荐毕节阿里店铺运营推荐济宁网站推广系统推荐廊坊关键词按天扣费哪家好坪地网站设计价格广元seo网站优化报价大同网站优化马鞍山关键词排名价格江门推广网站阿坝企业网站设计哪家好商丘SEO按天计费价格黔东南seo网站推广公司台州网站优化价格南京网络广告推广哪家好德州网站优化按天扣费沙井关键词排名多少钱南充百姓网标王推广报价盐城高端网站设计价格芜湖网站改版萍乡百度网站优化排名哪家好和田关键词按天计费大理百度网站优化公司歼20紧急升空逼退外机英媒称团队夜以继日筹划王妃复出草木蔓发 春山在望成都发生巨响 当地回应60岁老人炒菠菜未焯水致肾病恶化男子涉嫌走私被判11年却一天牢没坐劳斯莱斯右转逼停直行车网传落水者说“没让你救”系谣言广东通报13岁男孩性侵女童不予立案贵州小伙回应在美国卖三蹦子火了淀粉肠小王子日销售额涨超10倍有个姐真把千机伞做出来了近3万元金手镯仅含足金十克呼北高速交通事故已致14人死亡杨洋拄拐现身医院国产伟哥去年销售近13亿男子给前妻转账 现任妻子起诉要回新基金只募集到26元还是员工自购男孩疑遭霸凌 家长讨说法被踢出群充个话费竟沦为间接洗钱工具新的一天从800个哈欠开始单亲妈妈陷入热恋 14岁儿子报警#春分立蛋大挑战#中国投资客涌入日本东京买房两大学生合买彩票中奖一人不认账新加坡主帅:唯一目标击败中国队月嫂回应掌掴婴儿是在赶虫子19岁小伙救下5人后溺亡 多方发声清明节放假3天调休1天张家界的山上“长”满了韩国人?开封王婆为何火了主播靠辱骂母亲走红被批捕封号代拍被何赛飞拿着魔杖追着打阿根廷将发行1万与2万面值的纸币库克现身上海为江西彩礼“减负”的“试婚人”因自嘲式简历走红的教授更新简介殡仪馆花卉高于市场价3倍还重复用网友称在豆瓣酱里吃出老鼠头315晚会后胖东来又人满为患了网友建议重庆地铁不准乘客携带菜筐特朗普谈“凯特王妃P图照”罗斯否认插足凯特王妃婚姻青海通报栏杆断裂小学生跌落住进ICU恒大被罚41.75亿到底怎么缴湖南一县政协主席疑涉刑案被控制茶百道就改标签日期致歉王树国3次鞠躬告别西交大师生张立群任西安交通大学校长杨倩无缘巴黎奥运

深圳SEO优化公司 XML地图 TXT地图 虚拟主机 SEO 网站制作 网站优化

·