天堂国产午夜亚洲专区-少妇人妻综合久久蜜臀-国产成人户外露出视频在线-国产91传媒一区二区三区

基于SDN的網(wǎng)絡(luò)安全技術(shù)研究

發(fā)布時(shí)間:2019-04-18 12:41
【摘要】:近年來,重大網(wǎng)絡(luò)攻擊事件層見疊出,網(wǎng)絡(luò)安全已上升至國家安全的戰(zhàn)略層面。與此同時(shí),隨著大數(shù)據(jù)、云計(jì)算等技術(shù)的不斷發(fā)展,軟件定義網(wǎng)絡(luò)(Software Defined Networking,SDN)隨之興起。由于傳統(tǒng)網(wǎng)絡(luò)安全事件對SDN網(wǎng)絡(luò)依然具有較大的威脅,基于SDN網(wǎng)絡(luò)的攻擊應(yīng)對研究引起了學(xué)術(shù)界的關(guān)注。不過目前尚未出現(xiàn)一個(gè)準(zhǔn)確、快速、有效的輕量級安全方案。根據(jù)傳統(tǒng)網(wǎng)絡(luò)攻擊的分類,本文的研究內(nèi)容包括:非法報(bào)文攻擊、分布式拒絕服務(wù)(Distributed Denial of Service,DDoS)攻擊和端口掃描的應(yīng)對研究。為了防止非法報(bào)文攻擊對目的主機(jī)/服務(wù)器系統(tǒng)造成危害,本文利用非法報(bào)文攻擊包特異性高、區(qū)分明顯的特點(diǎn),提出了基于特征匹配的非法報(bào)文攻擊檢測應(yīng)對方案,在控制器進(jìn)行轉(zhuǎn)發(fā)決策前將解析出的packet-in相關(guān)信息與攻擊特征庫進(jìn)行匹配篩查。仿真結(jié)果表明,非法報(bào)文應(yīng)對方案能夠準(zhǔn)確識別IP分片攻擊和Land攻擊包,并將攻擊報(bào)文全部阻塞在攻擊源頭。SDN控制器具有單點(diǎn)脆弱性,DDoS攻擊對SDN網(wǎng)絡(luò)的影響更加嚴(yán)重。為了準(zhǔn)確檢測偽造源IP的DDoS攻擊,本文提出了基于熵值的DDoS攻擊應(yīng)對方案(Entropy-based DDoS Defense Mechanism,EDDM),該方案通過目的IP熵值的變化區(qū)分異常流量、再根據(jù)源MAC與源IP的對應(yīng)關(guān)系確認(rèn)攻擊并鎖定攻擊源。針對偽造了源MAC地址的DDoS攻擊,本文提出了一個(gè)新的DDoS攻擊應(yīng)對方案(Upgraded Entropy-based DDoS Defense Mechanism,Upgraded-EDDM),該方案首次提出將入端口熵值的變化作為攻擊檢測依據(jù),以目的IP熵值降低、入端口熵低于源IP熵作為攻擊判定標(biāo)準(zhǔn),并根據(jù)入端口與源MAC/源IP的對應(yīng)關(guān)系鎖定攻擊主機(jī)位置。通過仿真,證明Upgraded-EDDM方案能夠準(zhǔn)確識別偽造源MAC的UDP Flood攻擊,將攻擊流量阻塞在入端口,且其總體性能優(yōu)于EDDM方案。分布式反射拒絕服務(wù)(Distributed Reflection Denial of Service,DRDoS)攻擊和端口掃描在入端口、目的IP、目的端口號等特征的熵值上具有不同的變化特點(diǎn),由于它們具有與DDoS攻擊相同的熵值計(jì)算和異常排查過程,本文將Upgraded-EDDM方案擴(kuò)展成一個(gè)基于熵值的一體化安全方案(Integrated Entropy-based Attacks Defense Mechanism,Integrated-EADM),使其能夠識別并阻塞多種網(wǎng)絡(luò)攻擊。仿真結(jié)果表明,Integrated-EADM方案能夠快速、準(zhǔn)確地識別DRDoS攻擊和TCP SYN掃描,并將攻擊流量阻塞在源端。
[Abstract]:In recent years, major network attacks have emerged one after another, and network security has risen to the strategic level of national security. At the same time, with the continuous development of big data, cloud computing and other technologies, software-defined network (Software Defined Networking,SDN (Software definition Network) rises. Because the traditional network security events still pose a great threat to the SDN network, the research on the attack response based on the SDN network has attracted the attention of the academic circles. However, there is not yet an accurate, fast, effective lightweight security scheme. According to the classification of traditional network attacks, the research contents of this paper include: illegal packet attack, distributed denial of Service (Distributed Denial of Service,DDoS) attack and port scanning. In order to prevent the illegal message attack from causing harm to the target host / server system, this paper makes use of the high specificity and distinct distinction of the illegal message attack packet, and puts forward a response scheme of illegal message attack detection based on feature matching. The parsed packet-in correlation information is matched with the attack feature base before the controller makes forwarding decision. Simulation results show that the scheme can accurately identify IP fragmentation attack and Land attack packet, and block all the attack packets at the source of the attack. The DDoS controller has a single point of vulnerability, and the DDoS attack has a more serious impact on the SDN network. In order to detect the DDoS attack of the forgery source IP accurately, this paper proposes an entropy-based DDoS attack response scheme (Entropy-based DDoS Defense Mechanism,EDDM), which distinguishes abnormal traffic by the change of the destination IP entropy value. Then the attack is confirmed and locked according to the corresponding relationship between the source MAC and the source IP. In this paper, a new DDoS attack response scheme (Upgraded Entropy-based DDoS Defense Mechanism,Upgraded-EDDM) is proposed for the DDoS attack which forges the source MAC address. In this scheme, the change of the entropy value of the incoming port is first proposed as the basis of attack detection. The target IP entropy is reduced and the inlet entropy is lower than the source IP entropy as an attack criterion. The attack host location is locked according to the corresponding relationship between the inbound port and the source MAC/ source IP. The simulation results show that the Upgraded-EDDM scheme can accurately identify the UDP Flood attack of the forgery source MAC and block the attack traffic at the ingress port. The overall performance of the UDP Flood scheme is superior to that of the EDDM scheme. Distributed Reflectance denial of Service (Distributed Reflection Denial of Service,DRDoS) attacks and port scanning have different entropy values in terms of characteristics such as inbound port, destination IP, destination port number, and so on. Because they have the same entropy calculation and anomaly detection process as the DDoS attack, this paper extends the Upgraded-EDDM scheme to an all-in-one security scheme based on entropy (Integrated Entropy-based Attacks Defense Mechanism,Integrated-EADM). Enables it to identify and block multiple network attacks. The simulation results show that the Integrated-EADM scheme can quickly and accurately identify DRDoS attacks and TCP SYN scans, and block the attack traffic at the source end.
【學(xué)位授予單位】:電子科技大學(xué)
【學(xué)位級別】:碩士
【學(xué)位授予年份】:2017
【分類號】:TP393.08

【參考文獻(xiàn)】

相關(guān)期刊論文 前4條

1 史振華;劉外喜;楊家燁;;SDN架構(gòu)下基于ICMP流量的網(wǎng)絡(luò)異常檢測方法[J];計(jì)算機(jī)系統(tǒng)應(yīng)用;2016年04期

2 舒遠(yuǎn)仲;梅夢U,

本文編號:2460048


資料下載
論文發(fā)表

本文鏈接:http://sikaile.net/guanlilunwen/ydhl/2460048.html


Copyright(c)文論論文網(wǎng)All Rights Reserved | 網(wǎng)站地圖 |

版權(quán)申明:資料由用戶08c32***提供,本站僅收錄摘要或目錄,作者需要?jiǎng)h除請E-mail郵箱bigeng88@qq.com
一区二区三区日韩在线| 性感少妇无套内射在线视频| 欧美激情一区=区三区| 日本黄色录像韩国黄色录像| 青青操视频在线观看国产| 国内尹人香蕉综合在线| 亚洲精品偷拍视频免费观看| 久久国产精品亚州精品毛片| 91精品蜜臀一区二区三区| 扒开腿狂躁女人爽出白浆av | 国产欧美日韩精品一区二区| 中文字幕日韩欧美理伦片| 在线免费观看黄色美女| 黄色国产一区二区三区| 色婷婷在线精品国自产拍| 少妇视频一区二区三区| 亚洲一二三四区免费视频| 国产欧美日本在线播放| 国产精品亚洲一级av第二区 | 免费性欧美重口味黄色| 大香蕉伊人精品在线观看| 欧美乱视频一区二区三区| 国产丝袜极品黑色高跟鞋| 亚洲av熟女一区二区三区蜜桃| 一区二区三区18禁看| 欧美性欧美一区二区三区| 亚洲国产日韩欧美三级| 少妇肥臀一区二区三区| 日韩日韩欧美国产精品| 精品国产亚洲一区二区三区| 操白丝女孩在线观看免费高清| 午夜精品国产精品久久久| 国产一区二区久久综合| 国产午夜福利不卡片在线观看| 91欧美亚洲精品在线观看| 久久亚洲精品成人国产| 亚洲国产欧美精品久久| 老司机精品视频在线免费看| 99久热只有精品视频最新| 欧美日韩乱一区二区三区| 亚洲成人精品免费在线观看|