Method for Overflow Attack Defense of SDN Network Flow Table Based on Stochastic Differential Equation

被引:0
|
作者
Xinhui Zhao
Qingxian Wang
Zehui Wu
Rui Guo
机构
[1] Information Engineering University,State Key Laboratory of Mathematics Engineering & Advanced Computing
[2] Physical Education College of Zhengzhou University,Modern Education Technology Center
[3] Zhengzhou University of Light Industry,Engineering Training Center
来源
Wireless Personal Communications | 2021年 / 117卷
关键词
Stochastic differential equation; Overflow of SDN network flow table; SDN network attack; Defense;
D O I
暂无
中图分类号
学科分类号
摘要
In order to avoid the overflow problem of network flow table caused by hackers attacking the network in the process of using the network, a method for overflow attack defense of SDN network flow table based on stochastic differential equation is proposed. In this method, the stochastic differential equation is first proposed, and the drift coefficient and diffusion coefficient of the equation are expanded and adjusted by Taylor. By using the limit theorem, the spillover attack of SDN network is weakly converged to an approximate two-dimensional Markov diffusion process, and the improved stochastic differential equation is obtained. Then, according to the stochastic nature of SDN network attack, the stochastic differential equation is transformed into an amplitude equation, which is based on the amplitude. The equation establishes a SDN attack detection scheme based on flow table statistics, which detects the spillover attacks of SDN network flow tables. Finally, according to the test results, it is proposed to use other switches instead of network flow table overflow switches to control the data upload rate, thus reducing the possibility of network crash and meeting the attack defense requirements of flow table overflow. The simulation results show that the proposed method has better detection performance and shorter running time, and can provide help for network security related work.
引用
收藏
页码:3431 / 3447
页数:16
相关论文
共 50 条
  • [21] Metrics for network attack and defense effectiveness based on differential manifolds
    Zhao X.
    Jiang X.
    Zhao J.
    Xu H.
    Guo J.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2020, 60 (05): : 380 - 385
  • [22] Protection against Flow Table Overflow Attack in Software Defined Networks
    Noh, Sichul Kevin
    Kang, Minjae
    Park, Minho
    35TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2021), 2021, : 486 - 490
  • [23] A two-phase detection method against APT attack on flow table management in SDN
    Xinfeng He
    Shuchao Sun
    The Journal of Supercomputing, 2023, 79 : 15415 - 15434
  • [24] A two-phase detection method against APT attack on flow table management in SDN
    He, Xinfeng
    Sun, Shuchao
    JOURNAL OF SUPERCOMPUTING, 2023, 79 (14): : 15415 - 15434
  • [25] Network Defense Decision-Making Method Based on Stochastic Differential Game Model
    Huang, Shirui
    Zhang, Hengwei
    Wang, Jindong
    Huang, Jianming
    CLOUD COMPUTING AND SECURITY, PT V, 2018, 11067 : 504 - 516
  • [26] A proactive defense method against eavesdropping attack in SDN-based storage environment
    Liu, Yuming
    Wang, Yong
    Feng, Hao
    CYBERSECURITY, 2024, 7 (01):
  • [27] Flow Table Saturation Attack against Dynamic Timeout Mechanisms in SDN
    Shen, Yi
    Wu, Chunming
    Kong, Dezhang
    Cheng, Qiumei
    APPLIED SCIENCES-BASEL, 2023, 13 (12):
  • [28] SDN Mixed Mode Flow Table Release Mechanism Based on Network Topology
    Liu Chuan
    Hao Hanyong
    Li Binglin
    Wang Congying
    PROCEEDINGS OF THE 2017 6TH INTERNATIONAL CONFERENCE ON MEASUREMENT, INSTRUMENTATION AND AUTOMATION (ICMIA 2017), 2017, 154 : 280 - 285
  • [29] A Network Security Prediction Method Based on Attack Defense Tree
    Li, Junyi
    Wu, Yongdong
    Li, Yang
    Zhang, Ziwen
    Fouad, Hassan
    Altameem, Torki
    JOURNAL OF NANOELECTRONICS AND OPTOELECTRONICS, 2023, 18 (03) : 357 - 366
  • [30] POAGuard: A Defense Mechanism Against Preemptive Table Overflow Attack in Software-Defined Networks
    Liu, Yuming
    Wang, Yong
    Feng, Hao
    IEEE ACCESS, 2023, 11 : 123659 - 123676