Real-Time Security Services for SDN-based Datacenters

被引:0
|
作者
Varga, Pal [2 ]
Kathareios, Georgios [1 ]
Mate, Akos [1 ]
Clauberg, Rolf [1 ]
Anghel, Andreea [1 ]
Orosz, Peter [2 ]
Nagy, Balazs [3 ]
Tothfalusi, Tamas [2 ]
Kovacs, Laszlo [3 ]
Gusat, Mitch [1 ]
机构
[1] IBM Res Zurich, Zurich, Switzerland
[2] Budapest Univ Technol & Econ, Budapest, Hungary
[3] AITIA Int Inc, Budapest, Hungary
关键词
SDN; dDoS; switching; datacenter networking; online datapath monitoring; intrusion detection and prevention; ANOMALY DETECTION;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
While the scale, frequency and impact of the recent cyber-and DoS-attacks have all increased, the traditional security management systems are still supervised by human operators in the decisional loop. To cope with the new breed of machine-driven attacks -particularly those designed to overload the humans in the loop - the next-generation anomaly detection and attack mitigation schema, i.e. the network security management, must improve greatly in speed and accuracy: become machine-driven, too. As infrastructure we propose an FPGA-accelerated Network Function Virtualization that potentially enhances the current multi-Tbps switching fabrics with SDN-based security capabilities of vastly higher performance and scalability. As key novelties, we contribute (i) sub-ms detection lag (ii) of the top 9 Akamai attacks [1] with (iii) a real-time SDN feedback loop between a distributed programmable data plane and a centralized SDN controller, (iv) coupled via a global N:1 mirror. We validate the concept in an actual datacenter network with a new security application that can detect and mitigate real-world dDoS attacks, with lags from 430 us up to 3 ms - several orders of magnitude faster than before.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] A Framework for Security Enhancement in SDN-based Datacenters
    Ammar, Moustafa
    Rizk, Mohamed
    Abdel-Hamid, Ayman
    Aboul-Seoud, Ahmed K.
    [J]. 2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [2] An SDN-Based Approach to Design of Onboard Real-Time Networks
    Balashov, V.
    Kostenko, V.
    Ermakova, T.
    [J]. 2018 INTERNATIONAL SCIENTIFIC AND TECHNICAL CONFERENCE MODERN COMPUTER NETWORK TECHNOLOGIES (MONETEC 2018), 2018,
  • [3] Responsive Multipath TCP in SDN-based Datacenters
    Duan, Jingpu
    Wang, Zhi
    Wu, Chuan
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2015, : 5296 - 5301
  • [4] SDN-based real-time urban traffic analysis in VANET environment
    Bhatia, Jitendra
    Dave, Ridham
    Bhayani, Heta
    Tanwar, Sudeep
    Nayyar, Anand
    [J]. COMPUTER COMMUNICATIONS, 2020, 149 : 162 - 175
  • [5] A Scalable Real-Time SDN-Based MQTT Framework for Industrial Applications
    Shahri, E.
    Pedreiras, P.
    Almeida, L.
    [J]. IEEE OPEN JOURNAL OF THE INDUSTRIAL ELECTRONICS SOCIETY, 2024, 5 : 215 - 235
  • [6] SDN-based Security Services using Interface to Network Security Functions
    Kim, Jinyong
    Firoozjaei, Mahdi Daghmehchi
    Jeong, Jaehoon
    Kim, Hyoungshick
    Park, Jung-Soo
    [J]. 2015 INTERNATIONAL CONFERENCE ON ICT CONVERGENCE (ICTC), 2015, : 526 - 529
  • [7] SDN-Based Network Security Functions for VoIP and VoLTE Services
    Hyun, Daeyoung
    Kim, Jinyoug
    Jeong, Jaehoon
    Kim, Hyoungshick
    Park, Jungsoo
    Ahn, Taejin
    [J]. 2016 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC 2016): TOWARDS SMARTER HYPER-CONNECTED WORLD, 2016, : 298 - 302
  • [8] SDN-based Live VM Migration Across Datacenters
    Liu, Jiaqiang
    Li, Yong
    Jin, Depeng
    [J]. SIGCOMM'14: PROCEEDINGS OF THE 2014 ACM CONFERENCE ON SPECIAL INTEREST GROUP ON DATA COMMUNICATION, 2014, : 583 - 584
  • [9] SDN-based Live VM Migration Across Datacenters
    Liu, Jiaqiang
    Li, Yong
    Jin, Depeng
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (04) : 583 - 584
  • [10] SoD-MQTT: A SDN-Based Real-Time Distributed MQTT Broker
    Sylla, Tidiane
    Singh, Radheshyam
    Mendiboure, Leo
    Berger, Michael Stubert
    Berbineau, Marion
    Dittmann, Lars
    [J]. 2023 19TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS, WIMOB, 2023, : 92 - 97