华南理工大学学报(自然科学版) ›› 2020, Vol. 48 ›› Issue (11): 114-122.doi: 10.12141/j.issn.1000-565X.200282

• 计算机科学与技术 • 上一篇    下一篇

SDN 拓扑攻击及其防御

陆以勤毛中书2 程喆2† 覃健诚1 金冬子1 潘伟锵3   

  1. 1. 华南理工大学 电子与信息学院,广东 广州 510640; 2. 华南理工大学 计算机科学与工程学院,广东 广州 510640;3. 华南理工大学 信息网络工程研究中心,广东 广州 510640
  • 收稿日期:2020-06-03 修回日期:2020-06-17 出版日期:2020-11-25 发布日期:2020-11-05
  • 通信作者: 程喆(1980-),男,博士生,讲师,主要从事计算机网络、信息安全研究。 E-mail:csmzs1995@mail.scut.edu.cn
  • 作者简介:陆以勤(1968-),男,教授,博士生导师,主要从事 SDN、网络功能虚拟化、网络安全研究。E-mail: eeyqlu @scut.edu.cn
  • 基金资助:
    广东省重点领域研发计划项目 (2018B010113001,2019B010137001); 广州市科技计划项目 (201902010061)

Research on SDN Topology Attack and Its Defense Mechanism

LU Yiqin1 MAO Zhongshu2 CHENG Zhe2 QIN Jiancheng1 JIN Dongzi1 PAN Weiqiang3   

  1. 1. School of Electronic and Information Engineering,South China University of Technology,Guangzhou 510640,Guangdong,China; 2. School of Computer Science and Engineering,South China University of Technology,Guangzhou 510640,Guangdong,China; 3. Information and Network Engineering and Research Center,South China University of Technology,Guangzhou 510640,Guangdong,China
  • Received:2020-06-03 Revised:2020-06-17 Online:2020-11-25 Published:2020-11-05
  • Contact: 程喆(1980-),男,博士生,讲师,主要从事计算机网络、信息安全研究。 E-mail:csmzs1995@mail.scut.edu.cn
  • About author:陆以勤(1968-),男,教授,博士生导师,主要从事 SDN、网络功能虚拟化、网络安全研究。E-mail: eeyqlu @scut.edu.cn
  • Supported by:
    Supported by the R&D Program in Key Areas of Guangdong Province (2018B010113001,2019B010137001),Guangzhou Science and Technology Foundation of China (201902010061)

摘要: 为保护软件定义网络 (SDN) 中控制器的视图安全,特别是在网络链路状态变化环境中的全局视图完整性,提出一种 SDN 拓扑攻击防御机制———PolicyTopo。该机制引入信息熵理论构建模型验证网络链路延时变化,同时定义数据设备端口的安全性,在防御传统拓扑攻击的同时进一步解决了网络状态变化下拓扑攻击的防御问题。在虚拟环境和物理实验台上分别布署 PolicyTopo 并基于 Floodlight 控制器进行攻防测试,结果表明,PolicyTo-po 能动态有效保护网络状态变化中拓扑完整性,提高网络全局视图安全性。与同类主流防御机制比较结果表明,该机制减少大量网络资源开销,增强网络安全性、灵活性以及可扩展性。

关键词: 软件定义网络, 网络安全, SDN 控制器, 拓扑攻击

Abstract: A SDN topology attack defense mechanism———PolicyTopo was proposed in order to protect the view se-curity of the controller in software-defined networking (SDN),especially the global view integrity in the context of network link state changes. This mechanism introduces information entropy theory to build a model to verify the change of network link delay,and at the same time defines the security of data device ports. It also solves the de-fense problem of topology attacks under network state changes while defending against traditional topology attacks.PolicyTopo was deployed both on the virtual environment and the physical experiment platform,and the offensive and defensive tests were carried out based on Floodlight. The results show that PolicyTopo can dynamically and ef-fectively protect the topology integrity during network state changes and improve the security of the global view of the network. Compared with other mainstream defense mechanisms,this mechanism can largely reduce the cost of network resource and improve the security,flexibility and scalability of the network.

Key words: software-defined networking, cyber security, SDN controller, topology attack