首页 | 本学科首页   官方微博 | 高级检索  
     

SDN中基于机器学习的DDoS攻击协同防御
引用本文:尚 立,陈 明,张 磊,刘辛彤,石 泰,李保罡.SDN中基于机器学习的DDoS攻击协同防御[J].电力系统保护与控制,2021,49(16):170-176.
作者姓名:尚 立  陈 明  张 磊  刘辛彤  石 泰  李保罡
作者单位:国网河北省电力有限公司信息通信分公司,河北 石家庄 050000;华北电力大学,河北 保定 071003
基金项目:国家电网有限公司科技项目资助(SGHEXT00GCJS 2000167);国家自然科学基金项目资助(61971190)
摘    要:现在电力系统业务越来越多,传统的网络架构缺乏全局观、控制能力不强。软件定义网络(SDN)是一种新兴的网络架构,将SDN运用到电力系统中去,可以改变以往电力通信网的静态化格局,实现真正意义上的智能电网。然而,SDN这种体系结构容易受到分布式拒绝服务(DDo S)的威胁。采用卷积神经网络和SVM支持向量机相结合的方法来检测攻击。利用SDN控制器全局管理的特性,通过控制器提取相邻交换机之间的关联特征,使得交换机可以协同运作,提高检测精度。此外,为了可以实时观测网络的安全状况,设计了基于Influxdb和Grafana的轻量级网络监控系统。通过模拟攻击和正常流量来获取大量数据集,并和其他检测方法进行对比试验。实验结果表明,该模型有更高的检测率和更低的误报率,数据也可以实时上传到监控系统中,给管理者提供整个网络的视图,使得网络的管理更加便捷。

关 键 词:软件定义网络  入侵检测  机器学习  网络安全  卷积神经网络
收稿时间:2020/10/19 0:00:00
修稿时间:2021/1/18 0:00:00

Cooperative defense of DDoS attack based on machine learning in SDN
SHANG Li,CHEN Ming,ZHANG Lei,LIU Xintong,SHI Tai,LI Baogang.Cooperative defense of DDoS attack based on machine learning in SDN[J].Power System Protection and Control,2021,49(16):170-176.
Authors:SHANG Li  CHEN Ming  ZHANG Lei  LIU Xintong  SHI Tai  LI Baogang
Affiliation:1. Information and Communication Branch of State Grid Hebei Electric Power Co., Ltd., Shijiazhuang 050000, China; 2. North China Electric Power University, Baoding 071003, China
Abstract:There is an ever increasing number of services in the power system, and the traditional network architecture lacks an overall view and its control ability is not strong. The Software Defined Network (SDN) is an emerging network architecture. The application of SDN in a power system can change the static pattern of the previous power communication network and realize a real smart grid. However, the architecture of SDN is vulnerable to Distributed Denial of Service (DDoS) threats. A combination of convolutional neural network and Support Vector Machine (SVM) is used to detect attacks. Based on the features of global management of an SDN controller, the association features between adjacent switches are extracted by the controller, so that switches can cooperate in operation and detection efficiency and accuracy can be improved. In addition, a lightweight network monitoring system based on Influxdb and Grafana is designed for real-time observation of network security. A large number of data sets are obtained by simulating attacks and normal traffic, and comparing with other detection methods. The results show that the model has a higher detection rate and a lower false alarm rate, and the data can also be uploaded to the monitoring system in real time to provide managers with a view of the whole network, making the management of the network more convenient. This work is supported by the Sicence and Technology Project of State Grid Corporation of China (No. SGHEXT00GCJS2000167) and the National Natural Science Foundation of China (No. 61971190).
Keywords:software defined network  intrusion detection  machine learning  network security  convolutional neural network
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《电力系统保护与控制》浏览原始摘要信息
点击此处可从《电力系统保护与控制》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号