Prevention mechanism for infrastructure based Denial-of-Service attack over software Defined Network

Prevention mechanism for infrastructure based Denial-of-Service attack over software Defined Network
复制标题

基于软件定义网络的基础设施拒绝服务攻击的预防机制

DOI:
10.1109/ccaa.2015.7148442
复制
发表时间:
2015
期刊:
International Conference on Computing, Communication and Automation
影响因子:
--
通讯作者:
A. Agrawal
A. Agrawal
中科院分区:
--
文献类型:
--
作者:
Sandeep Singh;Raees Ahmad Khan;A. Agrawal

文献摘要

被引文献

相似文献

在软件定义的网络中,拒绝服务(DoS)或分布式拒绝服务(DDoS)攻击是试图使机器或网络资源对其目标用户不可用。因此,保护这种网络控制器免受来自网络内部或外部的攻击的需要是非常重要的。虽然开放流量中的网络设备也可能成为攻击者的攻击目标,因此需要一种预防机制,以避免出现数据包转发流畅的问题。在本研究任务中,我们在软件定义的网络上构建了一个基于基础设施的DoS攻击场景,并解决了流表中的漏洞,随后我们开发了一种预防机制,在攻击我们的网络之前,在攻击的初始阶段避免这种攻击。基于基础设施的DoS攻击场景使用Minet2.2.0开发,仿真平台为Linux Ubuntu-14.10 Utopicorn。
In software Defined Networking a Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) attack is an attempt to make a machine or network resources unavailable for its intended users. Hence the need for protection of such network controller against attacks from within or outside a network is very much important. Although network devices in open flow can also be targeted by attackers and so required a prevention mechanism in order to avoid problems in smooth packet forwarding. In this research task we compose an Infrastructure based DoS attacking scenario over the software defined network and address the vulnerabilities in flow table, and afterward we developed a prevention mechanism to avoid such kind of attack in its initial stage before harming our network. The scenarios for the Infrastructure based DoS attack are developed using Mininet 2.2.0 and platform used for the simulation is Linux Ubuntu-14.10 Utopic Unicorn.