Achieving a scalable and secure software defined network by identifiers separating and mapping

Achieving a scalable and secure software defined network by identifiers separating and mapping
复制标题

通过标识符分离和映射实现可扩展且安全的软件定义网络

DOI:
--
复制
发表时间:
2017
影响因子:
2.2
通讯作者:
Jia Chen
Jia Chen
中科院分区:
计算机科学3区
文献类型:
--
作者:
Mingxin Wang;Huachun Zhou;Jia Chen

文献摘要

相似文献

可扩展性和安全性一直是影响软件定义网络(SDN)发展的重要问题。在SDN中实现标识符分离和映射架构(ISMA),将网络划分为边缘网络和核心网络,是解决可扩展性和安全性问题的有效方案。本文提出了一种OpenFlow网络中流表项压缩的方法。我们修改了数据平面和控制平面的元素,实现了身份和位置的分离。我们定义了一个基于OpenFlow的接入转发单元连接边缘网络和核心网络,内部有一个映射流表,以及我们定义了一个基于OpenFlow的核心转发单元在核心网络中压缩流表规则的粗粒度转发。此外,我们提出了一种方法来检测和防止DDoS攻击的SDN网络中,通过分析的Packet_In消息与地图请求在中央控制器。在此基础上,设计了一个包含转发单元、中央控制器、映射模块和安全分析应用的原型系统。此外,我们比较了我们的方法与OpenFlow的性能,并使用原型和仿真环境验证的可行性和努力。该方法可以大大减少核心网中转发流表项的数量,并且可以在破坏受害者之前检测和阻止DDoS攻击。
Scalability and security are always the serious issues in fluencing the development of Software-Defined Network (SDN). Implementing Identifiers Separating and Mapping Architecture (ISMA) into SDN is a promising solution to improve the scalability and security problems by dividing the network into edge network and core network. In this paper, we propose an approach of ow table entries compression in OpenFlow network. We modify both the data plane and the control plane elements to implement the separating of identity and locator. We define an OpenFlow based access forwarding element connecting the edge network and core network which has a mapping ow table inside as well as we define an OpenFlow based core forwarding element in core network for compressing the ow table rules by coarse-grain forwarding. Besides, we propose an approach to detect and prevent DDoS attack in SDN network by analyzing the Packet_In messages with map request in the central controller. Based on the proposed approach, we design the prototype including forwarding elements and the central controller with mapping module and security analysis application. Additionally, we compare the performance of our approach with OpenFlow and verify the feasibility and effort using the prototype and simulation environment. The number of forwarding ow table entries in core network can be reduced dramatically and our approach can detect and prevent DDoS attack before undermining the victim.