课题基金 / 基金详情

软件定义网络的主动攻击与防御机制研究

批准号:
61402357
项目类别:
青年科学基金项目
资助金额:
27.0 万元
负责人:
张鹏
依托单位:
学科分类:
计算机网络
结题年份:
2017
批准年份:
2014
项目状态:
已结题
项目参与者:
周亚东、杨骥、乔思祎、孙成龙、吴海波、许琛

项目摘要

结项摘要

项目成果

张鹏的其他基金

相似基金

相关文献

中文摘要
软件定义网络(SDN)是一种新型计算机网络体系结构,具有中心式的网络控制、高效的数据转发和灵活的编程接口等特性,可极大的简化日趋复杂的网络管理任务。然而,正是由于数据/控制平面分离以中心控制的特点,SDN很容易受到主动攻击的威胁。考虑到SDN在国际学术和产业界的迅猛发展,以及在国民经济的广阔应用前景,对SDN的安全隐患特别是主动攻击进行系统的研究,并提出合理有效的防御机制显得十分必要和迫切。本项目从控制平面、控制信道、数据平面三个维度来分析SDN面临的主动攻击威胁,通过综合利用分布式哈希表、多队列调度、神经网络、同态消息验证码等技术手段,分别提出基于控制器策略完整性保障、异常OpenFlow消息检测和流量控制、轻量级的规则执行验证等研究方案,旨在对SDN中的策略篡改攻击、控制信道拒绝服务攻击、流表篡改攻击等主动攻击进行检测和防御,提高SDN网络的安全性、可信性和可靠性。
英文摘要
Software Defined Network (SDN) is a new network architecture, featured in centralized network control, highly-efficient data forwarding, and flexible programing interface. It is shown that SDN can greatly ease the increasing complicated task of network management. However, due to its decoupled control/data plane, and the centralized control mode, SDN is very vulnerable to many active attacks. Considering the worldwide attention from both the academia and industry, and the promising future in national economy, it is very urgent to systematically study the security vulnerabilities of SDN (especially active attacks faced by SDN), and come up with proper and effective counter-measures. This project approaches this problem from three aspects: control plane, control channel, and data plane. We propose a research plan including policy integrity guarantee for controllers, abnormal OpenFlow message detection and traffic control, and lightweight rule enforcement verification, by leveraging distributed hash table, multi-queue scheduling, neural network, and homomorphic MAC, etc. These security mechanisms can detect and prevent malicious modification of SDN policies, denial of service of control channel, and malicious modification of flow table, in order to enhance the security, trust, and reliability of SDN.
软件定义网络(SDN)是一种新型计算机网络体系结构,具有中心式的网络控制、高效的数据转发和灵活的编程接口等特性,可极大的简化日趋复杂的网络管理任务。然而,正是由于数据/控制平面分离以中心控制的特点,SDN很容易受到主动攻击的威胁。.本项目从控制平面、控制信道、数据平面三个维度来分析SDN面临的主动攻击威胁,取得了以下关键成果:(1)针对控制器策略篡改攻击,设计并实现了一种高性能的安全多控制器体系结构,可保证策略全局一致性,防止针对单个控制器策略篡改;(2)针对控制信道上的PacketIn 洪泛攻击,设计了基于动态多队列的公平调度方法,可有效隔离攻击交换机,保证控制器对正常请求的响应;(3)针对交换机流表篡改攻击,提出一种基于同态消息验证码的规则执行验证方法,可对控制器下发的规则是否在交换机正确执行进行验证,带宽开销相对于基于传统消息验证码方法减小近97%。
期刊论文列表
专著列表
科研奖励列表
会议论文列表
专利列表
An efficient online active learning algorithm for binary classification
一种高效的二元分类在线主动学习算法
DOI: 10.1016/j.patrec.2015.08.010
发表时间: 2015-12
期刊: Pattern Recognition Letters
影响因子: 5.1
作者: [Liu Dehua, Zhang Peng, Zheng Qinghua]
通讯作者: Zheng Qinghua
A secure and high-performance multi-controller architecture for software-defined networking
用于软件定义网络的安全高性能多控制器架构
DOI: 10.1631/fitee.1500321
发表时间: 2016-07
期刊: Frontiers of Information Technology & Electronic Engineering
影响因子: 3
作者: [Zhang, Peng, Xiong, Lei, Liu, Xin, Hu, Cheng-chen]
通讯作者: Hu, Cheng-chen
Capability-Based Security Enforcement in Named Data Networking
命名数据网络中基于能力的安全实施
DOI: 10.1109/tnet.2017.2715822
发表时间: 2017
期刊: IEEE/ACM Transactions on Networking
影响因子: --
作者: [Li Qi, Lee Patrick P C, Zhang Peng, Su Purui, He Liang, Ren Kui]
通讯作者: Ren Kui
DOI: 10.1109/tdsc.2015.2498603
发表时间: 2017-11
期刊: IEEE Transactions on Dependable and Secure Computing
影响因子: 7.3
作者: [Peng Zhang;Qi Li;P. Lee]
通讯作者: Peng Zhang;Qi Li;P. Lee
面向配置变更的网络验证方法研究
  • 批准号:
    --
  • 项目类别:
    面上项目
  • 资助金额:
    54万元
  • 批准年份:
    2022
  • 负责人:
    张鹏
  • 依托单位:
肿瘤相关成纤维细胞组蛋白乳酸化修饰促进胰腺癌恶性增殖的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    张鹏
  • 依托单位:
基于Sc-Fe-Si复合微合金化设计的Al-Cu-Ce合金热稳定性和力学性能调控规律及机理研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    54万元
  • 批准年份:
    2022
  • 负责人:
    张鹏
  • 依托单位:
析出相对微纳铝单晶强度离散性与位错雪崩的调控规律及微观机理研究
  • 批准号:
    52001249
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    24.0万元
  • 批准年份:
    2020
  • 负责人:
    张鹏
  • 依托单位:
国内基金
海外基金