Dynamic Game based Security framework in SDN-enabled Cloud Networking Environments

Dynamic Game based Security framework in SDN-enabled Cloud Networking Environments
复制标题

DOI:
10.1145/3040992.3040998
复制
发表时间:
2017-03
期刊:
Proceedings of the ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization
影响因子:
--
通讯作者:
Ankur Chowdhary;Sandeep Pisharody;Adel Alshamrani;Dijiang Huang
Ankur Chowdhary;Sandeep Pisharody;Adel Alshamrani;Dijiang Huang
中科院分区:
其他
文献类型:
--
作者:
Ankur Chowdhary;Sandeep Pisharody;Adel Alshamrani;Dijiang Huang

文献摘要

相似文献

SDN通过引入控制平面的可编程性和抽象提供了一种管理复杂网络的方法。所有网络都面临着针对关键基础设施和服务的攻击,例如DDoS攻击。在本研究中,我们利用SDN环境所提供的可编程性,提供了一个博弈论攻击分析和对策选择模型。该模型基于多玩家动态博弈中的奖惩机制。攻击者的网络带宽在一段时间内降低,玩家恢复合作后恢复正常。提出的解决方案基于纳什民间定理,该定理用于实现对DDoS流量一部分的攻击者的惩罚机制,并奖励合作的玩家,有效地执行网络管理员的预期结果。
SDN provides a way to manage complex networks by introducing programmability and abstraction of the control plane. All networks suffer from attacks to critical infrastructure and services such as DDoS attacks. We make use of the programmability provided by the SDN environment to provide a game theoretic attack analysis and countermeasure selection model in this research work. The model is based on reward and punishment in a dynamic game with multiple players. The network bandwidth of attackers is downgraded for a certain period of time, and restored to normal when the player resumes cooperation. The presented solution is based on Nash Folk Theorem, which is used to implement a punishment mechanism for attackers who are part of DDoS traffic, and reward for players who cooperate, in effect enforcing desired outcome for the network administrator.