![]() |
个人信息Personal Information
教授
博士生导师
硕士生导师
性别:女
毕业院校:大连理工大学
学位:博士
所在单位:软件学院、国际信息与软件学院
学科:计算机应用技术
联系方式:yaolin@dlut.edu.cn
电子邮箱:yaolin@dlut.edu.cn
DoS Mitigation Mechanism Based on Non-Cooperative Repeated Game for SDN
点击次数:
论文类型:会议论文
发表时间:2018-12-11
收录刊物:EI
卷号:2018-December
页面范围:612-619
关键字:Controllers; DOS; Entropy; Game theory; Network architecture; Packet networks, Centralized architecture; Incentive mechanism; Information entropy; Malicious packets; Non-cooperative repeated games; Normal operations; Packet loss rates; Simulation evaluation, Denial-of-service attack
摘要:Software defined network (SDN)can manage the whole network flexibly because of its programmability and logically centralized architecture. However, the centralized architecture of SDN makes it more vulnerable to Denial of Service (DoS)attack which is launched by sending a large number of malicious packet-in packets to consume the resources of the controller and data planes. In order to protect the normal operation of the network from DoS, we propose an effective DoS mitigation framework based on non-cooperative repeated game called PrioGuard. DoS can be detected based on the information entropy, packet-in rate and packet-in response rate. Furthermore, the penalty-incentive mechanism of repeated game is adopted to punish these attackers by lowering their priority in order to postpone their requests. The requests from attackers will be migrated to data plane cache, which can mitigate the interface cache of control plane and make the controller process the normal requests effectively. We have implemented a prototype system of PrioGuard. Simulation evaluations demonstrate that our scheme is very effective with less response time, less packet loss rate and lower controller load. © 2018 IEEE.