首页 | 本学科首页   官方微博 | 高级检索  
     

基于OpenFlow的SDN网络攻防方法综述
引用本文:武泽慧,魏强,王清贤. 基于OpenFlow的SDN网络攻防方法综述[J]. 计算机科学, 2017, 44(6): 121-132
作者姓名:武泽慧  魏强  王清贤
作者单位:解放军信息工程大学 郑州450001数学工程与先进计算国家重点实验室 郑州450001,解放军信息工程大学 郑州450001数学工程与先进计算国家重点实验室 郑州450001,解放军信息工程大学 郑州450001数学工程与先进计算国家重点实验室 郑州450001
摘    要:软件定义网络(Software Defined Network,SDN)的控制与转发分离、统一配置管理的特性使其网络部署的灵活性、网络管理的动态性以及网络传输的高效性均有大幅提升,但是其安全性方面的问题却比较突出。综述了基于OpenFlow的SDN在安全方面的研究现状,首先根据SDN的三层架构分析了其脆弱性,介绍SDN不同平面面临的安全威胁,并根据网络攻击的流程来介绍当前主要的攻击手段,包括目标网络探测、伪造欺骗实现网络接入以及拒绝服务攻击和信息窃取;其次,针对不同攻击环节,分别从探测阻断、系统加固、攻击防护3个方面对当前主要的防御手段进行论述;最后,从SDN潜在的攻击手段和可能的防御方法两方面来探讨未来SDN安全的研究趋势。

关 键 词:网络安全  软件定义网络  虚拟化  动态防御
收稿时间:2016-05-27
修稿时间:2016-09-27

Survey for Attack and Defense Approaches of OpenFlow-enabled Software Defined Network
WU Ze-hui,WEI Qiang and WANG Qing-xian. Survey for Attack and Defense Approaches of OpenFlow-enabled Software Defined Network[J]. Computer Science, 2017, 44(6): 121-132
Authors:WU Ze-hui  WEI Qiang  WANG Qing-xian
Affiliation:PLA Information Engineering University,Zhengzhou 450001,China State Key Laboratory of Mathematical Engineering and Advanced Computing,Zhengzhou 450001,China,PLA Information Engineering University,Zhengzhou 450001,China State Key Laboratory of Mathematical Engineering and Advanced Computing,Zhengzhou 450001,China and PLA Information Engineering University,Zhengzhou 450001,China State Key Laboratory of Mathematical Engineering and Advanced Computing,Zhengzhou 450001,China
Abstract:Software defined network (SDN) grants the network an omnipotent power to increase the flexibility of network deployment,the dynamic of network management and the efficiency of network transmission by centralizing the control plane and separating it with data plane.However,the security of SDN is still outstanding.In this paper,we aimed at analyzing and categorizing a number of relevant research works toward OpenFlow-enabled SDN security.We first provided an overview on threats of SDN with its three layers architecture,and further demonstrated their vulnerabilities within each layer.Thereafter,we presented existing SDN-related attacking approaches according to the procedures of network attacking,such as network probing,defraud inserting and remote controlling.And then we dedicated the next part of this paper to study and compared the current defense approaches underlying probe blocking,system strength,and attack defensing.Furthermore,we reviewed several potential attack and defensed methods as some foreseeable future research challenges.
Keywords:Cyber security  Software defined network  Virtualization  Dynamic defense
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号