簡易檢索 / 詳目顯示

研究生: 王靖元
Wang, Ching-Yuan
論文名稱: 在P4為基礎的SDN中可用於偵測DDoS攻擊之流量非對稱性研究
A Study on Traffic Asymmetry for Detecting DDoS Attack in P4-based SDN
指導教授: 蔡孟勳
Tsai, Meng-Hsun
學位類別: 碩士
Master
系所名稱: 電機資訊學院 - 資訊工程學系
Department of Computer Science and Information Engineering
論文出版年: 2021
畢業學年度: 109
語文別: 英文
論文頁數: 34
中文關鍵詞: 軟體定義網路 、資料蒐集 、分散式阻斷服務攻擊
外文關鍵詞: SDN, Data Collection, DDoS
相關次數: 點閱:233  下載:0 
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 隨著網路的普及,現代人越來越依賴網路來處理大量的事務,使得網路安全的重要性也不斷提升。在眾多對網路安全的威脅中,分散式阻斷服務攻擊長期都是研究者想解決的問題。隨著軟體定義網路的發展,越來越多的偵測方法也都被提出。但這些方法在蒐集資料的過程往往需要交換機傳送大量的資料到控制器,導致原本可能已經受到攻擊的網路每況愈下。為了解決這個問題,我們設計了一模組,在交換機上蒐集最可能與分散式阻斷服務攻擊相關的資料。根據過往的研究,一個IP位址在一段時間內所傳送與接收封包數量的不對稱性,對於偵測分散式阻斷服務攻擊來說是重要的特性。所以我們的模組目的即是蒐集在傳送與接收封包數量上最不對稱的IP位址。
    透過實驗,我們找到了運作這個模組最佳的參數。另外,我們也證實了在正常情況下,模組可以確實蒐集到有著上述特性的目標。最後,透過模擬實驗證實,我們的模組在有攻擊存在的環境下,相較其他相似方法可以更準確地蒐集攻擊者與被攻擊者的IP位址。

    With the widespread of the Internet, modern people increasingly rely on the In-ternet to complete a large amount of work, making the importance of Internet security continue to grow. Among many threats to network security, DDoS attacks have always been a problem that researchers want to solve. With the introduction of software-defined networking, more and more detection methods have been proposed. However,these methods often require switches to send a large amount of data to the controller,which may lead to a worse situation when the network is already under attack. To solve this problem, we designed a data structure to collect data most related to DDoS attacks on the switch. According to past researches, the asymmetry of the number of packets sent and received by an IP address in a period of time is an important feature for detecting DDoS attacks. Therefore, the goal of our model is to collect the most asymmetrical IP addresses in the number of packets sent and received. Through experiments, we have found the best parameters for running the model. In addition, we also confirmed that under normal circumstances, the model can indeed collect targets with the above characteristics. Finally, we proved that when there is an DDoS attack, our model can collect IP addresses of attackers and victims more accurately than other similar methods.

    中文摘要 i Abstract ii Acknowledgements iv Contents v List of Tables vii List of Figures viii 1 Introduction 1 2 Related Work 4 2.1 Statistic-based Method 4 2.2 Machine-Learning-based Method 5 2.3 Sketch-based Method 6 3 Proposed Scheme 9 3.1 Data Structure 9 3.2 Insertion 10 3.3 Eviction 11 4 Performance Evaluation 16 4.1 Model Tuning 16 4.1.1 Simulation Parameters 16 4.1.2 Tuning α_thr and β_thr 18 4.1.3 Tuning T_thr 20 4.2 Model Validity 23 4.3 Accuracy in Attack Scenario 25 4.4 Effect on Controller 26 5 Conclusions 29 References 30

    [1] A. Chadd, “Ddos attacks: past, present and future,”Network Security, vol. 2018,no. 7, pp. 13–15, 2018.
    [2] S. Mansfield-Devine, “The growth and evolution of ddos,”Network Security,vol. 2015, no. 10, pp. 13–20, 2015.
    [3] The Open Networking Foundation,OpenFlow Switch Specification, April 2015.
    [4] P. Bosshart, D. Daly, G. Gibb, M. Izzard, N. McKeown, J. Rexford, C. Schlesinger,D. Talayco, A. Vahdat, G. Varghese,et al., “P4: Programming protocol-independent packet processors,”ACM SIGCOMM Computer Communication Re-view, vol. 44, no. 3, pp. 87–95, 2014.
    [5] Y. Xu and Y. Liu, “Ddos attack detection under sdn context,” inIEEE INFOCOM2016 - The 35th Annual IEEE International Conference on Computer Communi-cations, pp. 1–9, 2016.
    [6] E. Biglar Beigi, H. Hadian Jazi, N. Stakhanova, and A. A. Ghorbani, “Towardseffective feature selection in machine learning-based botnet detection approaches,”in2014 IEEE Conference on Communications and Network Security, pp. 247–255,2014.
    [7] J. Mirkovic and P. Reiher, “A taxonomy of ddos attack and ddos defense mech-anisms,”ACM SIGCOMM Computer Communication Review, vol. 34, no. 2,pp. 39–53, 2004.
    [8] N. Dayal, P. Maity, S. Srivastava, and R. Khondoker, “Research trends in securityand ddos in sdn,”Security and Communication Networks, vol. 9, no. 18, pp. 6386–6411, 2016.
    [9] R. Wang, Z. Jia, and L. Ju, “An entropy-based distributed ddos detection mecha-nism in software-defined networking,” in2015 IEEE Trustcom/BigDataSE/ISPA,vol. 1, pp. 310–317, IEEE, 2015.
    [10] R. N. Carvalho, J. L. Bordim, and E. A. P. Alchieri, “Entropy-based dos attackidentification in sdn,” in2019 IEEE International Parallel and Distributed Pro-cessing Symposium Workshops (IPDPSW), pp. 627–634, IEEE, 2019.
    [11] R. Swami, M. Dave, and V. Ranga, “Defending ddos against software defined net-works using entropy,” in2019 4th International Conference on Internet of Things:Smart Innovation and Usages (IoT-SIU), pp. 1–5, IEEE, 2019.
    [12] C. E. Shannon, “A mathematical theory of communication,”The Bell systemtechnical journal, vol. 27, no. 3, pp. 379–423, 1948.
    [13] X. Yang, B. Han, Z. Sun, and J. Huang, “Sdn-based ddos attack detection withcross-plane collaboration and lightweight flow monitoring,” inGLOBECOM 2017-2017 IEEE Global Communications Conference, pp. 1–6, IEEE, 2017.
    [14] P. Wang, K.-M. Chao, H.-C. Lin, W.-H. Lin, and C.-C. Lo, “An efficient flowcontrol approach for sdn-based network threat detection and migration using sup-port vector machine,” in2016 IEEE 13th International Conference on e-BusinessEngineering (ICEBE), pp. 56–63, 2016.
    [15] M. Nobakht, V. Sivaraman, and R. Boreli, “A host-based intrusion detection andmitigation framework for smart home iot using openflow,” in2016 11th Interna-tional Conference on Availability, Reliability and Security (ARES), pp. 147–156,2016.
    [16] D. Hu, P. Hong, and Y. Chen, “Fadm: Ddos flooding attack detection and mitiga-tion system in software-defined networking,” inGLOBECOM 2017 - 2017 IEEEGlobal Communications Conference, pp. 1–7, 2017.
    [17] A. Sahi, D. Lai, Y. Li, and M. Diykh, “An efficient ddos tcp flood attack detectionand prevention system in a cloud environment,”IEEE Access, vol. 5, pp. 6036–6048, 2017.
    [18] M. Charikar, K. Chen, and M. Farach-Colton, “Finding frequent items in datastreams,” inInternational Colloquium on Automata, Languages, and Program-ming, pp. 693–703, Springer, 2002.
    [19] H. Liu, Y. Sun, and M. S. Kim, “Fine-grained ddos detection scheme based onbidirectional count sketch,” in2011 Proceedings of 20th International Conferenceon Computer Communications and Networks (ICCCN), pp. 1–6, IEEE, 2011.
    [20] G. Cormode and S. Muthukrishnan, “An improved data stream summary: thecount-min sketch and its applications,”Journal of Algorithms, vol. 55, no. 1,pp. 58–75, 2005.
    [21] G. Cormode and M. Muthukrishnan, “Approximating data with the count-minsketch,”IEEE software, vol. 29, no. 1, pp. 64–69, 2011.
    [22] V. Sivaraman, S. Narayana, O. Rottenstreich, S. Muthukrishnan, and J. Rexford,“Heavy-hitter detection entirely in the data plane,” inProceedings of the Sympo-sium on SDN Research, SOSR ’17, (New York, NY, USA), p. 164–176, Associationfor Computing Machinery, 2017.
    [23] T. Yang, J. Jiang, P. Liu, Q. Huang, J. Gong, Y. Zhou, R. Miao, X. Li, andS. Uhlig, “Elastic sketch: Adaptive and fast network-wide measurements,” inProceedings of the 2018 Conference of the ACM Special Interest Group on DataCommunication, SIGCOMM ’18, (New York, NY, USA), p. 561–575, Associationfor Computing Machinery, 2018.
    [24] C. Lapolli, J. Adilson Marques, and L. P. Gaspary, “Offloading real-time ddosattack detection to programmable data planes,” in2019 IFIP/IEEE Symposiumon Integrated Network and Service Management (IM), pp. 19–27, 2019.
    [25] A. Metwally, D. Agrawal, and A. El Abbadi, “Efficient computation of frequentand top-k elements in data streams,” inInternational conference on database the-ory, pp. 398–412, Springer, 2005.
    [26] J. Gordon, “Pareto process as a model of self-similar packet traffic,” inProceedingsof GLOBECOM ’95, vol. 3, pp. 2232–2236 vol.3, 1995.
    [27] D. Erhan and E. Anarım, “Bo ̆gazi ̧ci university distributed denial of servicedataset,”Data in Brief, vol. 32, p. 106187, 2020.
    [28] F. Huebner, D. Liu, and J. Fernandez, “Queueing performance comparisonof traffic models for internet traffic,” inIEEE GLOBECOM 1998 (Cat. NO.98CH36250), vol. 1, pp. 471–476 vol.1, 1998
    [29] S. Garc ́ıa, M. Grill, J. Stiborek, and A. Zunino, “An empirical comparison ofbotnet detection methods,”Computers Security, vol. 45, pp. 100–123, 2014.

    下載圖示
    2026-10-03公開
    QR CODE