首页 | 本学科首页   官方微博 | 高级检索  
     

SDN环境下DDoS攻击检测和缓解系统
引用本文:沈浩桐,魏松杰.SDN环境下DDoS攻击检测和缓解系统[J].计算机系统应用,2023,32(8):133-139.
作者姓名:沈浩桐  魏松杰
作者单位:南京理工大学 计算机科学与工程学院, 南京 210094
基金项目:工信部2020年工业互联网创新发展工程(TC200H01V); 国家自然科学基金(61802186, 61472189)
摘    要:分布式拒绝服务攻击(distributed denial of service, DDoS)是网络安全领域的一大威胁. 作为新型网络架构, 软件定义网络(software defined networking, SDN)的逻辑集中和可编程性为抵御DDoS攻击提供了新的思路. 本文设计并实现了一个轻量级的SDN环境下的DDoS攻击检测和缓解系统. 该系统使用熵值检测方法, 并通过动态阈值进行异常判断. 若异常, 系统将使用更精确的决策树模型进行检测. 最后, 控制器通过计算流的包对称率确定攻击源, 并下发阻塞流表项. 实验结果表明, 该系统能够及时响应DDoS攻击, 具有较高的检测成功率, 并能够有效遏制攻击.

关 键 词:软件定义网络|分布式拒绝服务攻击|检测|缓解|决策树|熵值
收稿时间:2023/2/6 0:00:00
修稿时间:2023/3/8 0:00:00

DDoS Attack Detection and Mitigation System in SDN Environment
SHEN Hao-Tong,WEI Song-Jie.DDoS Attack Detection and Mitigation System in SDN Environment[J].Computer Systems& Applications,2023,32(8):133-139.
Authors:SHEN Hao-Tong  WEI Song-Jie
Affiliation:School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing 210094, China
Abstract:Distributed denial of service (DDoS) attack is a major threat in the field of network security. As a new type of network architecture, the logic centralization and programmability of software defined networking (SDN) provide new ideas for defending against DDoS attacks. This study designs and implements a lightweight DDoS attack detection and mitigation system in SDN. The system uses the entropy detection method and judges the abnormality through the dynamic threshold. If the dynamic threshold is abnormal, the system will use a more accurate decision tree model for detection. Finally, the controller determines the attack source by calculating the packet symmetry rate of the flow and delivers the blocking flow entry. The experimental results show that the system can respond to DDoS attacks in time. It has a high detection success rate and can effectively contain attacks.
Keywords:software defined networking (SDN)|distributed denial of service (DDoS)|detection|mitigation|decision tree|entropy
点击此处可从《计算机系统应用》浏览原始摘要信息
点击此处可从《计算机系统应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号