a国产,中文字幕久久波多野结衣AV,欧美粗大猛烈老熟妇,女人av天堂

基于SDN的網(wǎng)絡(luò)安全技術(shù)研究

發(fā)布時(shí)間:2019-04-18 12:41
【摘要】:近年來,重大網(wǎng)絡(luò)攻擊事件層見疊出,網(wǎng)絡(luò)安全已上升至國家安全的戰(zhàn)略層面。與此同時(shí),隨著大數(shù)據(jù)、云計(jì)算等技術(shù)的不斷發(fā)展,軟件定義網(wǎng)絡(luò)(Software Defined Networking,SDN)隨之興起。由于傳統(tǒng)網(wǎng)絡(luò)安全事件對SDN網(wǎng)絡(luò)依然具有較大的威脅,基于SDN網(wǎng)絡(luò)的攻擊應(yīng)對研究引起了學(xué)術(shù)界的關(guān)注。不過目前尚未出現(xiàn)一個(gè)準(zhǔn)確、快速、有效的輕量級安全方案。根據(jù)傳統(tǒng)網(wǎng)絡(luò)攻擊的分類,本文的研究內(nèi)容包括:非法報(bào)文攻擊、分布式拒絕服務(wù)(Distributed Denial of Service,DDoS)攻擊和端口掃描的應(yīng)對研究。為了防止非法報(bào)文攻擊對目的主機(jī)/服務(wù)器系統(tǒng)造成危害,本文利用非法報(bào)文攻擊包特異性高、區(qū)分明顯的特點(diǎn),提出了基于特征匹配的非法報(bào)文攻擊檢測應(yīng)對方案,在控制器進(jìn)行轉(zhuǎn)發(fā)決策前將解析出的packet-in相關(guān)信息與攻擊特征庫進(jìn)行匹配篩查。仿真結(jié)果表明,非法報(bào)文應(yīng)對方案能夠準(zhǔn)確識別IP分片攻擊和Land攻擊包,并將攻擊報(bào)文全部阻塞在攻擊源頭。SDN控制器具有單點(diǎn)脆弱性,DDoS攻擊對SDN網(wǎng)絡(luò)的影響更加嚴(yán)重。為了準(zhǔn)確檢測偽造源IP的DDoS攻擊,本文提出了基于熵值的DDoS攻擊應(yīng)對方案(Entropy-based DDoS Defense Mechanism,EDDM),該方案通過目的IP熵值的變化區(qū)分異常流量、再根據(jù)源MAC與源IP的對應(yīng)關(guān)系確認(rèn)攻擊并鎖定攻擊源。針對偽造了源MAC地址的DDoS攻擊,本文提出了一個(gè)新的DDoS攻擊應(yīng)對方案(Upgraded Entropy-based DDoS Defense Mechanism,Upgraded-EDDM),該方案首次提出將入端口熵值的變化作為攻擊檢測依據(jù),以目的IP熵值降低、入端口熵低于源IP熵作為攻擊判定標(biāo)準(zhǔn),并根據(jù)入端口與源MAC/源IP的對應(yīng)關(guān)系鎖定攻擊主機(jī)位置。通過仿真,證明Upgraded-EDDM方案能夠準(zhǔn)確識別偽造源MAC的UDP Flood攻擊,將攻擊流量阻塞在入端口,且其總體性能優(yōu)于EDDM方案。分布式反射拒絕服務(wù)(Distributed Reflection Denial of Service,DRDoS)攻擊和端口掃描在入端口、目的IP、目的端口號等特征的熵值上具有不同的變化特點(diǎn),由于它們具有與DDoS攻擊相同的熵值計(jì)算和異常排查過程,本文將Upgraded-EDDM方案擴(kuò)展成一個(gè)基于熵值的一體化安全方案(Integrated Entropy-based Attacks Defense Mechanism,Integrated-EADM),使其能夠識別并阻塞多種網(wǎng)絡(luò)攻擊。仿真結(jié)果表明,Integrated-EADM方案能夠快速、準(zhǔn)確地識別DRDoS攻擊和TCP SYN掃描,并將攻擊流量阻塞在源端。
[Abstract]:In recent years, major network attacks have emerged one after another, and network security has risen to the strategic level of national security. At the same time, with the continuous development of big data, cloud computing and other technologies, software-defined network (Software Defined Networking,SDN (Software definition Network) rises. Because the traditional network security events still pose a great threat to the SDN network, the research on the attack response based on the SDN network has attracted the attention of the academic circles. However, there is not yet an accurate, fast, effective lightweight security scheme. According to the classification of traditional network attacks, the research contents of this paper include: illegal packet attack, distributed denial of Service (Distributed Denial of Service,DDoS) attack and port scanning. In order to prevent the illegal message attack from causing harm to the target host / server system, this paper makes use of the high specificity and distinct distinction of the illegal message attack packet, and puts forward a response scheme of illegal message attack detection based on feature matching. The parsed packet-in correlation information is matched with the attack feature base before the controller makes forwarding decision. Simulation results show that the scheme can accurately identify IP fragmentation attack and Land attack packet, and block all the attack packets at the source of the attack. The DDoS controller has a single point of vulnerability, and the DDoS attack has a more serious impact on the SDN network. In order to detect the DDoS attack of the forgery source IP accurately, this paper proposes an entropy-based DDoS attack response scheme (Entropy-based DDoS Defense Mechanism,EDDM), which distinguishes abnormal traffic by the change of the destination IP entropy value. Then the attack is confirmed and locked according to the corresponding relationship between the source MAC and the source IP. In this paper, a new DDoS attack response scheme (Upgraded Entropy-based DDoS Defense Mechanism,Upgraded-EDDM) is proposed for the DDoS attack which forges the source MAC address. In this scheme, the change of the entropy value of the incoming port is first proposed as the basis of attack detection. The target IP entropy is reduced and the inlet entropy is lower than the source IP entropy as an attack criterion. The attack host location is locked according to the corresponding relationship between the inbound port and the source MAC/ source IP. The simulation results show that the Upgraded-EDDM scheme can accurately identify the UDP Flood attack of the forgery source MAC and block the attack traffic at the ingress port. The overall performance of the UDP Flood scheme is superior to that of the EDDM scheme. Distributed Reflectance denial of Service (Distributed Reflection Denial of Service,DRDoS) attacks and port scanning have different entropy values in terms of characteristics such as inbound port, destination IP, destination port number, and so on. Because they have the same entropy calculation and anomaly detection process as the DDoS attack, this paper extends the Upgraded-EDDM scheme to an all-in-one security scheme based on entropy (Integrated Entropy-based Attacks Defense Mechanism,Integrated-EADM). Enables it to identify and block multiple network attacks. The simulation results show that the Integrated-EADM scheme can quickly and accurately identify DRDoS attacks and TCP SYN scans, and block the attack traffic at the source end.
【學(xué)位授予單位】:電子科技大學(xué)
【學(xué)位級別】:碩士
【學(xué)位授予年份】:2017
【分類號】:TP393.08

【參考文獻(xiàn)】

相關(guān)期刊論文 前4條

1 史振華;劉外喜;楊家燁;;SDN架構(gòu)下基于ICMP流量的網(wǎng)絡(luò)異常檢測方法[J];計(jì)算機(jī)系統(tǒng)應(yīng)用;2016年04期

2 舒遠(yuǎn)仲;梅夢U,

本文編號:2460048


資料下載
論文發(fā)表

本文鏈接:http://www.wukwdryxk.cn/guanlilunwen/ydhl/2460048.html


Copyright(c)文論論文網(wǎng)All Rights Reserved | 網(wǎng)站地圖 |

版權(quán)申明:資料由用戶08c32***提供,本站僅收錄摘要或目錄,作者需要刪除請E-mail郵箱bigeng88@qq.com
国产精品5c5c5c| 久久精品无码专区免费青青| 97在线观看| 18禁黄污无遮挡无码网站| 色综合色天天久久婷婷基地| 久久夜色精品亚洲| 国产av精品色哟哟| 欧美黑人又粗又大高潮喷水| 国产精品偷伦视频免费观看了| 黑水县| 久热综合| 色诱亚洲精品久久久久久| 亚洲色欲无码一区二区三区| 中文字幕久久精品无码| 999国内少妇毛片视频| 亚洲另类无码一区二区三区| 欧美jizz18性欧美| 日日夜夜大香蕉| 黑帮大佬和我的365日| 久久婷婷综合缴情亚洲狠狠| 一本一道AV无码中文字幕| 奇米影视第四色首页| 免费精品一区二区三区| 91狠狠狠狠狠狠狠狠| 日本靠逼视频| 翁h狠狠躁死你h| 免费无码一区二区三区| 无码人妻丰满熟妇区免费| 日本高清成本人视频一区 | 亚洲一区二区三区中文字幂| 国产成人无码aⅴ片在线观看| 伊川县| 久碰精品少妇中文字幕av| 欧美日韩国产黄片| 欧美综合视频| 欧美精品中文字幕亚洲专区| 久久久久99精品成人片三人毛片| 亚洲人成网站在线观看播放| 国产精品美女久久久久AV福利| 国产精品一区波多野结衣| 嫩草影院|