Sdn-Inspired, Real-Time Botnet Detection And Flow-Blocking At Isp And Enterprise-Level

2015 IEEE International Conference on Communications (ICC)(2015)

引用 8|浏览45
暂无评分
摘要
Infected machines pose threats to not only their users, but also their network owners (ISPs and enterprises). To neutralize the effect of these infected machines, common solutions span two ends of an architectural spectrum; either fully distributed solutions that are host-based, or completely centralized appliances at the network core. We present NetworkRadar, inspired by an SDN-enabled ISP framework, that operates in between these extremes and contains the benefits of both these approaches. We perform data-plane intensive event monitoring at aggregation points close to customers, and maintain a centralized control plane for correlating and high-granularity blocking of malicious bot activity. Here we present the architecture of our solution and evaluate a prototype deployment over an isolated slice of an ISP network, showing its viability due to a negligible (<1%) impact on customer throughput and its control plane scaling linearly to the customer base.
更多
查看译文
关键词
SDN-inspired botnet detection,real-time botnet detection,flow-blocking,ISP,enterprise-level,NetworkRadar,data-plane intensive event monitoring,aggregation points,prototype deployment
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要