A scalable anomaly detection and mitigation architecture for legacy networks via an OpenFlow middlebox

A scalable anomaly detection and mitigation architecture for legacy networks via an OpenFlow middlebox
复制标题

通过 OpenFlow 中间盒为传统网络提供可扩展的异常检测和缓解架构

DOI:
10.1002/sec.1368
复制
发表时间:
2016
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
B. Maglaris
B. Maglaris
中科院分区:
--
文献类型:
--
作者:
Kostas Giotis;G. Androulidakis;B. Maglaris

文献摘要

被引文献

相似文献

在本文中,我们调查的适用性,插入一个OpenFlow中间盒,以增强远程触发黑洞路由机制,减轻分布式拒绝服务DDoS攻击的传统网络。具体而言,我们提出了一种模块化架构,该架构在网络功能虚拟化的背景下利用软件定义网络的网络可编程性,部署能够操纵和过滤恶意流量的按需虚拟化网络功能VNF。利用OpenFlow控制功能,我们在每个流级别上匹配和处理流量,保持与受害者的连接,同时将缓解过程推向上游,朝向受影响网络的边缘。为此,开发了一种多级异常检测和识别机制,在检测到攻击时精确定位受害者。随后,虚拟化网络功能指示边缘路由器将去往受害者的所有流量转发到OpenFlow交换机,OpenFlow交换机充当能够过滤由OpenFlow控制器识别的恶意流量的中间盒,同时保留良性流量。该架构的实施和评估的基础上,包含痕迹的真实的DDoS攻击和正常的背景流量从我们的大学校园网络的数据集的组合。我们的分析说明了恶意源使用的互联网协议前缀的清晰聚类;因此,我们实现了最长的公共前缀聚合算法,以实现所提出的缓解过程的扩展,克服由于OpenFlow设备的硬件限制所带来的限制。我们的分析表明,所提出的模块化和可扩展的模式可以有效地识别DDoS攻击的受害者和过滤恶意流量,而不会耗尽系统和网络资源。版权所有© 2015约翰威利父子有限公司.
In this paper, we investigate the applicability of inserting an OpenFlow middlebox to enhance the remotely triggered black hole routing mechanism, to mitigate distributed denial of service DDoS attacks in legacy networks. Specifically, we propose a modular architecture that exploits the network programmability of software-defined networking within the context of network functions virtualization, deploying on-demand virtualized network functions VNFs capable to manipulate and filter malicious traffic. Leveraging on the OpenFlow control functionality, we match and handle traffic on a per-flow level, preserving connectivity to/from the victim while pushing the mitigation process upstream, towards the edge of the affected network. To that end, a multilevel anomaly detection and identification mechanism was developed, pinpointing the victim in case an attack is detected. Subsequently, a virtualized network function instructs the edge router to forward all traffic destined to the victim to an OpenFlow switch, acting as a middlebox capable to filter malicious traffic identified by an OpenFlow controller, while preserving benign flows. The proposed architecture was implemented and evaluated based on the combination of datasets containing traces of real DDoS attacks and normal background traffic from our university campus network. Our analysis illustrated a clear clustering of Internet protocol prefixes used by malicious sources; thus, we implemented a longest common prefix aggregation algorithm to enable scaling of the proposed mitigation process, overcoming constraints due to hardware limitations of OpenFlow devices. Our analysis verifies that the proposed modular and scalable schema can efficiently identify DDoS attack victims and filter malicious traffic, without exhausting system and network resources. Copyright © 2015 John Wiley & Sons, Ltd.