本文已被:浏览 681次 下载 1418次
Received:November 15, 2021 Revised:December 13, 2021
Received:November 15, 2021 Revised:December 13, 2021
中文摘要: 软件定义网络(software-defined networking, SDN)实现了控制层和转发层设备的分离, 但控制转发的解耦使得SDN网络中不同层次设备面临新型的DDoS攻击风险. 为了解决上述问题, 本文提出了一种SDN环境下基于改进D-S理论的DDoS攻击检测方法, 用于检测以SDN控制器和交换机为目标的DDoS攻击. 在改进的算法中, 本文使用离散因子和纯度因子衡量D-S证据源之间的冲突. 同时, 结合纯度因子和离散因子调整D-S证据理论的证据源, 调整后的证据源将通过Dempster规则融合得到DDoS攻击检测结果. 实验结果表明本文提出的方法具有较高的精度.
Abstract:Although the separation of the devices in the control layer and the forwarding layer can be achieved by software-defined networking (SDN), the decoupling of the two layers exposes the devices in different layers of the network to new types of distributed denial of service (DDoS) attacks. To solve the above problem, this study proposes a DDoS attack detection method based on the improved Dempster-Shafer (D-S) theory for detecting DDoS attacks aimed at SDN controllers and switches in an SDN environment. In the improved algorithm, the discrete factor and the purity factor are used to measure the conflicts among D-S evidence sources. Meanwhile, the evidence sources of the D-S evidence theory are adjusted according to the two factors, and the DDoS attack detection result is obtained with the adjusted evidence sources in light of Dempster’s rule of combination. Experimental results show that the proposed method achieves high detection precision.
keywords: software-defined networking (SDN) distributed denial of service (DDoS) OpenFlow Dempster-Shafer (D-S) evidence theory anomaly detection
文章编号: 中图分类号: 文献标志码:
基金项目:国家自然科学基金(62102111); 贵州省科技计划(黔科合基础[2020]1Y267); 赛尔网络下一代互联网技术创新项目(NGII20161007)
引用文本:
王聪,崔允贺,高鸿峰.SDN环境下基于改进D-S理论的DDoS攻击检测.计算机系统应用,2022,31(8):354-360
WANG Cong,CUI Yun-He,GAO Hong-Feng.DDoS Attack Detection Based on Improved D-S Theory in SDN.COMPUTER SYSTEMS APPLICATIONS,2022,31(8):354-360
王聪,崔允贺,高鸿峰.SDN环境下基于改进D-S理论的DDoS攻击检测.计算机系统应用,2022,31(8):354-360
WANG Cong,CUI Yun-He,GAO Hong-Feng.DDoS Attack Detection Based on Improved D-S Theory in SDN.COMPUTER SYSTEMS APPLICATIONS,2022,31(8):354-360