Detecting Malicious Packet Drops And Misroutings Using Header Space Analysis

2016 8TH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST)(2016)

引用 1|浏览58
暂无评分
摘要
Software Defined Networking (SDN) provides a logically centralized view of the state of the network, and as a result opens up new ways to manage and monitor networks. In this paper we introduce a novel approach to network intrusion detection in SDNs that takes advantage of these attributes. Our approach can detect compromised routers that produce faulty messages, copy or steal traffic or maliciously drop certain types of packets. To identify these attacks and the affected switches, we correlate the forwarding state of network-i.e. installed forwarding rules-with the forwarding status of packets-i.e. the actual route packets take in the network and detect anomaly in routes. Thus, our approach turns the network itself into a big intrusion detection system. We have evaluated our approach on topologies from real networks by developing an application over OpenDaylight SDN controller and detected simulated dropping and duplicating attacks in these networks.
更多
查看译文
关键词
malicious packet drops,malicious packet misroutings,header space analysis,software defined networking,network intrusion detection,compromised routers,faulty messages,copy traffic,steal traffic,installed forwarding rules,anomaly detection,OpenDaylight SDN controller,detected simulated dropping,duplicating attacks
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要