节点文献

基于排队论的软件定义网络中拒绝服务攻击抵御机制

DDoS Attack Resistant Mechanism Based on Queueing Theory in Software-Defined Network

【作者】 张帆;

【导师】 袁斌;

【作者基本信息】 华中科技大学 , 网络空间安全, 2023, 硕士

【摘要】 软件定义网络是一种数据面和控制面分离的新型网络架构,具有突出的可编程性、可扩展性和灵活性,被广泛用于云数据中心的部署。然而,软件定义网络也面临着许多安全威胁,其中最典型的便是分布式拒绝服务攻击。攻击者利用软件定义网络数据平面转发机制的缺陷,大量消耗软件定义网络设备有限的处理资源,影响正常网络转发服务,进而严重影响数据中心网络的可用性、可靠性和安全性。现有的防御方法多倾向于使用攻击检测,而这种被动式防御方案耗时较长且准确性不高,还可能出现在采取应对措施之前,攻击就已导致网络服务不可用,而无法按原计划施行防御策略的情况。为了避免上述问题,提出了一种基于排队论的软件定义网络中拒绝服务攻击抵御机制。首先,在网络流量分布方面,网络中不同位置的转发节点所承担的网络流量压力不同,基于网络拓扑和路由选择分析,对网络流量分布情况进行建模,估算各转发节点需要承担的流量大小。其次,对软件定义网络的数据包处理机制进行分析,利用M/M/c排队论模型对数据包在交换机和控制器中的处理过程进行建模,估算数据包处理过程在交换机和控制器中的平均等待时间。最后,将软件定义网络中数据包处理过程的排队论模型与网络流量分布估算模型相结合,分析得出抵御攻击成功的约束条件,并利用约束条件对抵御攻击所需的设备资源量进行估算,从而指导网络管理者合理配置和投入网络资源,实现服务质量可保障的拒绝服务攻击抵御。基于理论模型,使用模拟仿真环境搭设软件定义网络实验平台,对比真实网络中的数据与模型计算结果,证明了模型的可行性。对攻击抵御机制进行了量化分析,证明了机制在评估拒绝服务攻击与防御效果上的有效性,以及对网络管理者合理配置资源的指导意义。

【Abstract】 Software-defined network(SDN)presents a novel network architecture separating its data plane and control plane,which makes it outstandingly programmable,scalable,flexible,and widely used in various data centers.However,SDNs also suffer from many types of security threats.The most typical one is the distributed denial of service(DDo S)attack,which commonly exploits the flaw of the forwarding mechanism in the SDN data plane and drains the resources of SDN devices causing unpredictable and catastrophic consequences to the availability,reliability,and security of data center networks.Many prior defense schemes have been proposed from the perspective of attack detection.However,such defense schemes are known to suffer from time consumption and unpromising accuracy,which could result in an unavailable network service before specific countermeasures are taken.To address this issue,a DDo S attack resistant mechanism based on queueing theory in SDN is proposed.Firstly,in terms of network traffic distribution,the network traffic on forwarding nodes at different locations in the network is different.Based on the analyses of network topology and routing,the network traffic distribution is modeled to estimate the traffic on each forwarding node.Secondly,the packet processing mechanism of the software-defined network is analyzed,and the packet processing processes in the switch and controller are modeled using the M/M/c queuing theory model to estimate the average waiting time of the packet processing processes in the switch and controller.Finally,the queueing theory model of packet processing in software-defined networks is combined with the network traffic distribution model to analyze the constraints on the success of resisting attacks.And the amount of resources required to resist attacks is estimated using the constraints,so as to guide network managers in the rational investment of network device resources to resist DDo S attacks with guaranteed quality of service(Qo S).Based on the theoretical model,an SDN network is built with a simulated environment.The data from the actual SDN network are compared with the estimated results obtained from the model calculations,which prove the feasibility of the model.Quantitative analyses of the DDo S attack resistant mechanism are conducted to demonstrate its effectiveness in assessing the effectiveness of DDo S attacks and defenses,as well as its relevance in guiding network managers in the rational allocation of resources.

  • 【分类号】TP393.08;O226
节点文献中: 

本文链接的文献网络图示:

本文的引文网络