...
首页> 外文期刊>International journal of communication systems >SYN-Guard: An effective counter for SYN flooding attack in software-defined networking
【24h】

SYN-Guard: An effective counter for SYN flooding attack in software-defined networking

机译:SYN-Guard:软件定义网络中针对SYN泛洪攻击的有效计数器

获取原文
获取原文并翻译 | 示例
           

摘要

In software-defined networking (SDN), TCP SYN flooding attack is considered as one of the most effective attacks to perform control plane and target server saturation. In this attack, an attacker generates a large number of malicious SYN requests, and because of the absence of the forwarding rules, the data plane switches have to forward these SYN messages to the controller. This excessive forwarding causes congestion over the communication channel between a data plane and control plane, and it also exhausts computational resources at both the planes. In this paper, we propose a novel countermeasure called SYN-Guard to detect and prevent SYN flooding in SDN networks. We fully implement SYN-Guard on the SDN controller to validate the incoming TCP connection requests. The controller installs forwarding rules for the SYN requests that successfully clear the validation test of SYN-Guard. The host of the fake SYN request is detected, and SYN-Guard prevents it from sending any further SYN requests to the data plane switch. The performance evaluation done using the simulation results shows that SYN-Guard exhibits low side effect for genuine TCP requests, and when compared with standard SDN and state-of-art proposals, it reduces the average response time up to 21% during an ongoing SYN flooding attack.
机译:在软件定义网络(SDN)中,TCP SYN泛洪攻击被视为执行控制平面和目标服务器饱和的最有效攻击之一。在这种攻击中,攻击者会生成大量恶意SYN请求,并且由于缺少转发规则,因此数据平面交换机必须将这些SYN消息转发到控制器。这种过多的转发导致数据平面和控制平面之间的通信信道上的拥塞,并且还耗尽了两个平面上的计算资源。在本文中,我们提出了一种名为SYN-Guard的新型对策,用于检测和防止SDN网络中的SYN泛洪。我们在SDN控制器上完全实现SYN-Guard,以验证传入的TCP连接请求。控制器为成功清除SYN-Guard验证测试的SYN请求安装转发规则。检测到伪造的SYN请求的主机,并且SYN-Guard阻止它向数据平面交换机发送任何其他SYN请求。使用仿真结果进行的性能评估表明,SYN-Guard对真正的TCP请求显示出较低的副作用,并且与标准SDN和最新建议相比,在进行中的SYN期间,平均响应时间最多可减少21%洪水攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号