首页 | 本学科首页   官方微博 | 高级检索  
     

基于Renyi熵的Openflow信道链路泛洪攻击主动防御方法
引用本文:蔡佳晔,张红旗,宋佳良. 基于Renyi熵的Openflow信道链路泛洪攻击主动防御方法[J]. 计算机应用研究, 2019, 36(6)
作者姓名:蔡佳晔  张红旗  宋佳良
作者单位:信息工程大学,郑州,450001;信息工程大学,郑州,450001;信息工程大学,郑州,450001
基金项目:国家"863"计划资助项目(2012AA012704);郑州市科技领军人才资助项目(131PLJRC644)
摘    要:针对新型链路泛洪攻击,提出一种基于Renyi熵的Openflow信道链路泛洪攻击主动防御方法。运用Renyi熵分析攻击者在构建Openflow信道Linkmap过程中产生的ICMP超时报文数量变化。一旦出现攻击前兆由流量监控服务器向控制器发出攻击预警,控制器启动交换机-控制器连接迁移机制,将交换机迁移至新的控制器下并使用新的Openflow信道与之通信。实验证明,主动防御方法能有效避免控制器与交换机之间通信链路受到链路泛洪攻击的影响,确保控制器和交换机能持续交互提供网络服务,增强了SDN网络的健壮性。

关 键 词:链路泛洪攻击  OpenFlow信道  Renyi熵  主动防御
收稿时间:2017-12-10
修稿时间:2018-03-04

Active defense method of Openflow channel link flooding attack based on Renyi entropy
Cai Jia ye,Zhang Hong qi and Song Jia liang. Active defense method of Openflow channel link flooding attack based on Renyi entropy[J]. Application Research of Computers, 2019, 36(6)
Authors:Cai Jia ye  Zhang Hong qi  Song Jia liang
Affiliation:Information Engineering University,,
Abstract:For defending the new link flooding attack, this paper proposed an active defense method of Openflow channel link flooding based on Renyi entropy. Analyzing the changes in the number of ICMP timeout messages produced by an attacker in the construction of the Openflow channel Linkmap from Renyi entropy. Once attacks precursor was detected, flow monitoring server sends an attack warning to the controller, then controller start switch-controller connection migration mechanism, migrate the switch to a new controller and communicate with the new Openflow channel. Experimental results show that the active defense method can effectively avoid the impact of link flooding attack between controller and switch and ensure that controller and switch can provide continuous network services and enhance the robustness of SDN network.
Keywords:link-flooding attack  Openflow channel  Renyi entropy  active defense
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机应用研究》浏览原始摘要信息
点击此处可从《计算机应用研究》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号