Real-Time Security Services for SDN-based Datacenters

被引:0
|
作者
Varga, Pal [2 ]
Kathareios, Georgios [1 ]
Mate, Akos [1 ]
Clauberg, Rolf [1 ]
Anghel, Andreea [1 ]
Orosz, Peter [2 ]
Nagy, Balazs [3 ]
Tothfalusi, Tamas [2 ]
Kovacs, Laszlo [3 ]
Gusat, Mitch [1 ]
机构
[1] IBM Res Zurich, Zurich, Switzerland
[2] Budapest Univ Technol & Econ, Budapest, Hungary
[3] AITIA Int Inc, Budapest, Hungary
关键词
SDN; dDoS; switching; datacenter networking; online datapath monitoring; intrusion detection and prevention; ANOMALY DETECTION;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
While the scale, frequency and impact of the recent cyber-and DoS-attacks have all increased, the traditional security management systems are still supervised by human operators in the decisional loop. To cope with the new breed of machine-driven attacks -particularly those designed to overload the humans in the loop - the next-generation anomaly detection and attack mitigation schema, i.e. the network security management, must improve greatly in speed and accuracy: become machine-driven, too. As infrastructure we propose an FPGA-accelerated Network Function Virtualization that potentially enhances the current multi-Tbps switching fabrics with SDN-based security capabilities of vastly higher performance and scalability. As key novelties, we contribute (i) sub-ms detection lag (ii) of the top 9 Akamai attacks [1] with (iii) a real-time SDN feedback loop between a distributed programmable data plane and a centralized SDN controller, (iv) coupled via a global N:1 mirror. We validate the concept in an actual datacenter network with a new security application that can detect and mitigate real-world dDoS attacks, with lags from 430 us up to 3 ms - several orders of magnitude faster than before.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] A Framework for Security Enhancement in SDN-based Datacenters
    Ammar, Moustafa
    Rizk, Mohamed
    Abdel-Hamid, Ayman
    Aboul-Seoud, Ahmed K.
    2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [2] An SDN-Based Approach to Design of Onboard Real-Time Networks
    Balashov, V.
    Kostenko, V.
    Ermakova, T.
    2018 INTERNATIONAL SCIENTIFIC AND TECHNICAL CONFERENCE MODERN COMPUTER NETWORK TECHNOLOGIES (MONETEC 2018), 2018,
  • [3] Responsive Multipath TCP in SDN-based Datacenters
    Duan, Jingpu
    Wang, Zhi
    Wu, Chuan
    2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2015, : 5296 - 5301
  • [4] SDN-based real-time urban traffic analysis in VANET environment
    Bhatia, Jitendra
    Dave, Ridham
    Bhayani, Heta
    Tanwar, Sudeep
    Nayyar, Anand
    COMPUTER COMMUNICATIONS, 2020, 149 : 162 - 175
  • [5] A Scalable Real-Time SDN-Based MQTT Framework for Industrial Applications
    Shahri, E.
    Pedreiras, P.
    Almeida, L.
    IEEE OPEN JOURNAL OF THE INDUSTRIAL ELECTRONICS SOCIETY, 2024, 5 (215-235): : 215 - 235
  • [6] SDN-based Security Services using Interface to Network Security Functions
    Kim, Jinyong
    Firoozjaei, Mahdi Daghmehchi
    Jeong, Jaehoon
    Kim, Hyoungshick
    Park, Jung-Soo
    2015 INTERNATIONAL CONFERENCE ON ICT CONVERGENCE (ICTC), 2015, : 526 - 529
  • [7] SDN-Based Network Security Functions for VoIP and VoLTE Services
    Hyun, Daeyoung
    Kim, Jinyoug
    Jeong, Jaehoon
    Kim, Hyoungshick
    Park, Jungsoo
    Ahn, Taejin
    2016 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC 2016): TOWARDS SMARTER HYPER-CONNECTED WORLD, 2016, : 298 - 302
  • [8] SDN-based Live VM Migration Across Datacenters
    Liu, Jiaqiang
    Li, Yong
    Jin, Depeng
    SIGCOMM'14: PROCEEDINGS OF THE 2014 ACM CONFERENCE ON SPECIAL INTEREST GROUP ON DATA COMMUNICATION, 2014, : 583 - 584
  • [9] SDN-based Live VM Migration Across Datacenters
    Liu, Jiaqiang
    Li, Yong
    Jin, Depeng
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (04) : 583 - 584
  • [10] SoD-MQTT: A SDN-Based Real-Time Distributed MQTT Broker
    Sylla, Tidiane
    Singh, Radheshyam
    Mendiboure, Leo
    Berger, Michael Stubert
    Berbineau, Marion
    Dittmann, Lars
    2023 19TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS, WIMOB, 2023, : 92 - 97