Real-Time Security Services for SDN-based Datacenters

被引:0
|
作者
Varga, Pal [2 ]
Kathareios, Georgios [1 ]
Mate, Akos [1 ]
Clauberg, Rolf [1 ]
Anghel, Andreea [1 ]
Orosz, Peter [2 ]
Nagy, Balazs [3 ]
Tothfalusi, Tamas [2 ]
Kovacs, Laszlo [3 ]
Gusat, Mitch [1 ]
机构
[1] IBM Res Zurich, Zurich, Switzerland
[2] Budapest Univ Technol & Econ, Budapest, Hungary
[3] AITIA Int Inc, Budapest, Hungary
关键词
SDN; dDoS; switching; datacenter networking; online datapath monitoring; intrusion detection and prevention; ANOMALY DETECTION;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
While the scale, frequency and impact of the recent cyber-and DoS-attacks have all increased, the traditional security management systems are still supervised by human operators in the decisional loop. To cope with the new breed of machine-driven attacks -particularly those designed to overload the humans in the loop - the next-generation anomaly detection and attack mitigation schema, i.e. the network security management, must improve greatly in speed and accuracy: become machine-driven, too. As infrastructure we propose an FPGA-accelerated Network Function Virtualization that potentially enhances the current multi-Tbps switching fabrics with SDN-based security capabilities of vastly higher performance and scalability. As key novelties, we contribute (i) sub-ms detection lag (ii) of the top 9 Akamai attacks [1] with (iii) a real-time SDN feedback loop between a distributed programmable data plane and a centralized SDN controller, (iv) coupled via a global N:1 mirror. We validate the concept in an actual datacenter network with a new security application that can detect and mitigate real-world dDoS attacks, with lags from 430 us up to 3 ms - several orders of magnitude faster than before.
引用
收藏
页数:9
相关论文
共 50 条
  • [31] An SDN-based Firewall for Networks with Varying Security Requirements
    Rezaei, Ghazal
    Hashemi, Massoud Reza
    2021 26TH INTERNATIONAL COMPUTER CONFERENCE, COMPUTER SOCIETY OF IRAN (CSICC), 2021,
  • [32] SDN-Based Security Framework for the IoT in Distributed Grid
    Gonzalez, Carlos
    Charfadine, Salim Mahamat
    Flauzac, Olivier
    Nolot, Florent
    2016 INTERNATIONAL MULTIDISCIPLINARY CONFERENCE ON COMPUTER AND ENERGY SCIENCE (SPLITECH), 2016, : 81 - 85
  • [33] SDN-based VANETs, Security Attacks, Applications, and Challenges
    Arif, Muhammad
    Wang, Guojun
    Geman, Oana
    Balas, Valentina Emilia
    Tao, Peng
    Brezulianu, Adrian
    Chen, Jianer
    APPLIED SCIENCES-BASEL, 2020, 10 (09):
  • [34] SDN-Based Data Transfer Security for Internet of Things
    Liu, Yanbing
    Kuang, Yao
    Xiao, Yunpeng
    Xu, Guangxia
    IEEE INTERNET OF THINGS JOURNAL, 2018, 5 (01): : 257 - 268
  • [35] A SDN-based Architecture for Horizontal Internet of Things Services
    Li, Yuhong
    Su, Xiang
    Riekki, Jukka
    Kanter, Theo
    Rahmani, Rahim
    2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,
  • [36] Seamless Handover and Security Solution for Real-Time Services
    Diab, Wafaa Bou
    Tohme, Samir
    2009 11TH IEEE INTERNATIONAL SYMPOSIUM ON MULTIMEDIA (ISM 2009), 2009, : 363 - 368
  • [37] SDN-based security management of multiple WoT Smart Spaces
    Saad El Jaouhari
    Ahmed Bouabdallah
    Andreea Ancuta Corici
    Journal of Ambient Intelligence and Humanized Computing, 2021, 12 : 9081 - 9096
  • [38] Privacy-Preserving and Security in SDN-Based IoT: A Survey
    Ahmadvand, Hossein
    Lal, Chhagan
    Hemmati, Hadi
    Sookhak, Mehdi
    Conti, Mauro
    IEEE ACCESS, 2023, 11 : 44772 - 44786
  • [39] An SDN-Based Dynamic Security Architecture for Space Information Networks
    Wang, Ziqi
    Cui, Baojiang
    Yao, Shen
    Jiang, Meiyi
    SPACE INFORMATION NETWORKS, SINC 2019, 2020, 1169 : 99 - 111
  • [40] SDN-based optimal security service path construction mechanism
    Liu Y.
    Chen X.
    Lu Y.
    Qiao W.
    Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University, 2019, 46 (01): : 158 - 165