Real-Time Security Services for SDN-based Datacenters

被引:0
|
作者
Varga, Pal [2 ]
Kathareios, Georgios [1 ]
Mate, Akos [1 ]
Clauberg, Rolf [1 ]
Anghel, Andreea [1 ]
Orosz, Peter [2 ]
Nagy, Balazs [3 ]
Tothfalusi, Tamas [2 ]
Kovacs, Laszlo [3 ]
Gusat, Mitch [1 ]
机构
[1] IBM Res Zurich, Zurich, Switzerland
[2] Budapest Univ Technol & Econ, Budapest, Hungary
[3] AITIA Int Inc, Budapest, Hungary
关键词
SDN; dDoS; switching; datacenter networking; online datapath monitoring; intrusion detection and prevention; ANOMALY DETECTION;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
While the scale, frequency and impact of the recent cyber-and DoS-attacks have all increased, the traditional security management systems are still supervised by human operators in the decisional loop. To cope with the new breed of machine-driven attacks -particularly those designed to overload the humans in the loop - the next-generation anomaly detection and attack mitigation schema, i.e. the network security management, must improve greatly in speed and accuracy: become machine-driven, too. As infrastructure we propose an FPGA-accelerated Network Function Virtualization that potentially enhances the current multi-Tbps switching fabrics with SDN-based security capabilities of vastly higher performance and scalability. As key novelties, we contribute (i) sub-ms detection lag (ii) of the top 9 Akamai attacks [1] with (iii) a real-time SDN feedback loop between a distributed programmable data plane and a centralized SDN controller, (iv) coupled via a global N:1 mirror. We validate the concept in an actual datacenter network with a new security application that can detect and mitigate real-world dDoS attacks, with lags from 430 us up to 3 ms - several orders of magnitude faster than before.
引用
收藏
页数:9
相关论文
共 50 条
  • [21] RecFlow: SDN-based receiver-driven flow scheduling in datacenters
    Khan, Aadil Zia
    Qazi, Ihsan Ayyub
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2020, 23 (01): : 289 - 306
  • [22] Explainable Security in SDN-Based IoT Networks
    Sarica, Alper Kaan
    Angin, Pelin
    SENSORS, 2020, 20 (24) : 1 - 30
  • [23] SDN-Based Broadband Network for Cloud Services
    Xiongyan Tang
    Pei Zhang
    Chang Cao
    ZTE Communications, 2014, 12 (02) : 18 - 22
  • [24] An Adaptive SDN-Based Load Balancing Method for Edge/Fog-Based Real-Time Healthcare Systems
    Jasim, Ahmed M.
    Al-Raweshidy, Hamed
    IEEE SYSTEMS JOURNAL, 2024, 18 (02): : 1139 - 1150
  • [25] Work in Progress: Dynamic Offloading of Soft Real-time Tasks in SDN-based Fog Computing Environment
    Kumar, Niraj
    Mondal, Arijit
    2022 INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE (EMSOFT 2022), 2022, : 7 - 8
  • [26] SDATP: An SDN-Based Adaptive Transmission Protocol for Time-Critical Services
    Chen, Jiayin
    Ye, Qiang
    Quan, Wei
    Yan, Si
    Phu Thinh Do
    Zhuang, Weihua
    Shen, Xuemin
    Li, Xu
    Rao, Jaya
    IEEE NETWORK, 2020, 34 (03): : 154 - 162
  • [27] SDN Based Security Services
    ZHANG Yunyong
    XU Lei
    TAO Ye
    ZTE Communications, 2018, 16 (04) : 9 - 14
  • [28] Synaptic: a Formal Checker for SDN-based Security Policies
    Schnepf, Nicolas
    Badonnel, Remi
    Lahmadi, Abdelkader
    Merz, Stephan
    NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,
  • [29] Real-time QoS-aware Routing Scheme in SDN-based Robotic Cyber-Physical Systems
    Jhaveri, Rutvij H.
    Tan, Rui
    Ramani, Sagar V.
    2019 IEEE 5TH INTERNATIONAL CONFERENCE ON MECHATRONICS SYSTEM AND ROBOTS (ICMSR 2019), 2019, : 18 - 23
  • [30] Research on SDN-based IoT Security Architecture Model
    Zheng, Shiji
    PROCEEDINGS OF 2019 IEEE 8TH JOINT INTERNATIONAL INFORMATION TECHNOLOGY AND ARTIFICIAL INTELLIGENCE CONFERENCE (ITAIC 2019), 2019, : 575 - 579