跳到主要导航 跳到搜索 跳到主要内容

Adaptive Detection Method for Packet-In Message Injection Attack in SDN

  • Xinyu Zhan
  • , Mingsong Chen
  • , Shui Yu
  • , Yue Zhang*
  • *此作品的通讯作者
  • East China Normal University
  • University of Technology Sydney

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Packet-In message injection attack is severe in Software Defined Network (SDN), which will cause a single point of failure of the centralized controller and the crash of the entire network. Nowadays, there are many detection methods for it, including entropy detection and so on. We propose an adaptive detection method to proactively defend against this attack. We establish a Poisson probability distribution detection model to find the attack and use the flow table filter to mitigate it. We also use the EWMA method to update the expectation value of the model to adapt the actual network conditions. Our method has no need to send additional packets to request the switch information. The experiment results show that there is 92% true positive rate in case of attack with random destination IP packets injected, and true positive rate is 98.2% under the attack with random source IP packets injected.

源语言英语
主期刊名Algorithms and Architectures for Parallel Processing - 19th International Conference, ICA3PP 2019, Proceedings
编辑Sheng Wen, Albert Zomaya, Laurence T. Yang
出版商Springer
482-495
页数14
ISBN(印刷版)9783030389604
DOI
出版状态已出版 - 2020
活动19th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2019 - Melbourne, 澳大利亚
期限: 9 12月 201911 12月 2019

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
11945 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议19th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2019
国家/地区澳大利亚
Melbourne
时期9/12/1911/12/19

指纹

探究 'Adaptive Detection Method for Packet-In Message Injection Attack in SDN' 的科研主题。它们共同构成独一无二的指纹。

引用此