Risk and avoidance strategy for blocking mechanism of SDN-based security service

2019 21st International Conference on Advanced Communication Technology (ICACT)(2019)

引用 1|浏览3
暂无评分
摘要
Software-Defined Network (SDN) is the dynamic network technology to address the issues of traditional networks. It provides centralized view of the whole network through decoupling the control planes and data planes of a network. Most SDN-based security services globally detect and block a malicious host based on IP address. However, the IP address is not verified during the forwarding process in most cases and SDN-based security service may block a normal host with forged IP address in the whole network, which means false-positive. In this paper, we introduce an attack scenario that uses forged packets to make the security service consider a victim host as an attacker so that block the victim. We also introduce cost-effective risk avoidance strategy.
更多
查看译文
关键词
Security,IP networks,Switches,Protocols,Monitoring,IEC Standards
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要