System and method for detecting and mitigating arp attacks based on sdn cloud environment

A cloud environment, real-time detection technology, applied in the field of network security, can solve problems such as the inability to meet the flexibility and variability of cloud networks, increase the complexity of cloud network environments, and the accuracy is not 100%, to monitor and mitigate ARP storm attacks , the effect of reducing transmission and processing, enhancing fault tolerance and performance

Active Publication Date: 2022-02-25
NANJING UNIV
View PDF4 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Some solutions are aimed at specific dynamic IP allocation scenarios or specific static IP allocation scenarios, which cannot meet the flexibility and variability of cloud networks
Some solutions need to set up an independent server to assist the controller in handling ARP security in the cloud network, which further increases the complexity of the complex cloud network environment
There are also solutions that extract the attack traffic characteristics from a large number of ARP attacks to detect the security of ARP traffic, but the accuracy of such solutions is not 100%.
Obviously, the existing methods for preventing ARP attacks have their own defects and cannot meet the increasing network security requirements.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • System and method for detecting and mitigating arp attacks based on sdn cloud environment
  • System and method for detecting and mitigating arp attacks based on sdn cloud environment
  • System and method for detecting and mitigating arp attacks based on sdn cloud environment

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0054] The technical solutions provided by the present invention will be described in detail below in conjunction with specific examples. It should be understood that the following specific embodiments are only used to illustrate the present invention and are not intended to limit the scope of the present invention. In addition, the steps shown in the flow diagrams of the figures may be performed in a computer system, such as a set of computer-executable instructions, and, although a logical order is shown in the flow diagrams, in some cases, the sequence may be different. The steps shown or described are performed in the order herein.

[0055] figure 1 What is shown is the network topology formed when the present invention is implemented on the cloud. The invention is based on the SDN technology, and uses a controller cluster to control and manage the SDN switch in the cloud network. Providers provide users with various services in the form of virtual machines, but each use...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The present invention provides a system and method for detecting and mitigating ARP attacks based on an SDN cloud environment. The system includes: a network information maintenance module, a real-time detection and defense module, a timing monitoring and mitigation module, and a flow entry control module; the method includes: The start-up stage; the stage of obtaining network information; the stage of real-time detection and defense of ARP attacks; the stage of regular monitoring and mitigation of ARP attacks. The present invention uses SDN technology to detect ARP request packets and ARP reply packets, detects ARP spoofing attacks in real time by analyzing ARP packets, and then discards forged packets to prevent ARP spoofing attacks from harming the host, and can also obtain ARP traffic at regular intervals to detect The traffic statistics data of the port of the edge SDN switch can identify the ARP storm attack, and can block the traffic of the corresponding port in time, alleviate the impact of the ARP storm attack on the cloud network, and comprehensively protect the security of the cloud computing network.

Description

technical field [0001] The invention belongs to the technical field of network security, relates to a cloud network security technology, in particular to an address resolution protocol (ARP) attack detection and mitigation system based on a software-defined network (SDN) and an implementation method thereof. Background technique [0002] Cloud computing is a widely used form of providing services. Users can obtain servers, platforms, applications and other computing resources from the resource pool provided by cloud providers on demand. On the cloud, users can store data and use services conveniently and safely, because the cloud provider will be responsible for the maintenance of the cloud platform, and will also use various technologies to ensure the security of the services used by users. Therefore, cloud computing has become the most basic technology that companies around the world rely on. At the same time, cloud network security is also a current hot issue. [0003] A...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Patents(China)
IPC IPC(8): H04L9/40H04L61/103
CPCH04L63/1408H04L63/1441H04L63/1483H04L61/103
Inventor 伏晓孙思娴骆斌
Owner NANJING UNIV
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products