计算机科学与技术

SDN 拓扑攻击及其防御

展开
  • 1. 华南理工大学 电子与信息学院,广东 广州 510640; 2. 华南理工大学 计算机科学与工程学院,广东 广州 510640;3. 华南理工大学 信息网络工程研究中心,广东 广州 510640
陆以勤(1968-),男,教授,博士生导师,主要从事 SDN、网络功能虚拟化、网络安全研究。E-mail: eeyqlu @scut.edu.cn

收稿日期: 2020-06-03

  修回日期: 2020-06-17

  网络出版日期: 2020-06-19

基金资助

广东省重点领域研发计划项目 (2018B010113001,2019B010137001); 广州市科技计划项目 (201902010061)

Research on SDN Topology Attack and Its Defense Mechanism

Expand
  • 1. School of Electronic and Information Engineering,South China University of Technology,Guangzhou 510640,Guangdong,China; 2. School of Computer Science and Engineering,South China University of Technology,Guangzhou 510640,Guangdong,China; 3. Information and Network Engineering and Research Center,South China University of Technology,Guangzhou 510640,Guangdong,China
陆以勤(1968-),男,教授,博士生导师,主要从事 SDN、网络功能虚拟化、网络安全研究。E-mail: eeyqlu @scut.edu.cn

Received date: 2020-06-03

  Revised date: 2020-06-17

  Online published: 2020-06-19

Supported by

Supported by the R&D Program in Key Areas of Guangdong Province (2018B010113001,2019B010137001),Guangzhou Science and Technology Foundation of China (201902010061)

摘要

为保护软件定义网络 (SDN) 中控制器的视图安全,特别是在网络链路状态变化环境中的全局视图完整性,提出一种 SDN 拓扑攻击防御机制———PolicyTopo。该机制引入信息熵理论构建模型验证网络链路延时变化,同时定义数据设备端口的安全性,在防御传统拓扑攻击的同时进一步解决了网络状态变化下拓扑攻击的防御问题。在虚拟环境和物理实验台上分别布署 PolicyTopo 并基于 Floodlight 控制器进行攻防测试,结果表明,PolicyTo-po 能动态有效保护网络状态变化中拓扑完整性,提高网络全局视图安全性。与同类主流防御机制比较结果表明,该机制减少大量网络资源开销,增强网络安全性、灵活性以及可扩展性。

本文引用格式

陆以勤, 毛中书, 程喆, 等 . SDN 拓扑攻击及其防御[J]. 华南理工大学学报(自然科学版), 2020 , 48(11) : 114 -122 . DOI: 10.12141/j.issn.1000-565X.200282

Abstract

A SDN topology attack defense mechanism———PolicyTopo was proposed in order to protect the view se-curity of the controller in software-defined networking (SDN),especially the global view integrity in the context of network link state changes. This mechanism introduces information entropy theory to build a model to verify the change of network link delay,and at the same time defines the security of data device ports. It also solves the de-fense problem of topology attacks under network state changes while defending against traditional topology attacks.PolicyTopo was deployed both on the virtual environment and the physical experiment platform,and the offensive and defensive tests were carried out based on Floodlight. The results show that PolicyTopo can dynamically and ef-fectively protect the topology integrity during network state changes and improve the security of the global view of the network. Compared with other mainstream defense mechanisms,this mechanism can largely reduce the cost of network resource and improve the security,flexibility and scalability of the network.
文章导航

/