Unlock instant, AI-driven research and patent intelligence for your innovation.

Ddos detection method and system based on neural network in sdn network

A neural network and detection method technology, applied in the field of network security, can solve problems such as increasing costs, violating the principle of decoupling and decoupling of control and forwarding planes, and reducing network utilization.

Active Publication Date: 2021-09-07
CHONGQING UNIV OF POSTS & TELECOMM +1
View PDF7 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, there are still deficiencies in some aspects
For example, the first method of using SVM to detect DDoS only uses a small number of data samples for training. It cannot detect new types of attacks combined in multiple ways, and the detection accuracy needs to be improved. More importantly, in actual scenarios, DDoS The amount of data is often 20G or even higher, so the actual effect of this method is not good
The second is to implement DDoS detection at the entrance of network traffic by modifying the OpenFlow switch. This method can indeed deal with DDoS traffic in the most timely manner, but this will greatly increase the cost and violate the decoupling and principle of separating the control and forwarding planes.
[0004] Most DDoS detections are based on the principle of intrusion detection, using machine learning algorithms for direct detection. If DDoS attacks do not occur and such complex and load-increasing DDoS detections are performed, network utilization will be greatly reduced.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Ddos detection method and system based on neural network in sdn network
  • Ddos detection method and system based on neural network in sdn network
  • Ddos detection method and system based on neural network in sdn network

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0036] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some, not all, embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0037] The present invention proposes a DDoS detection method based on neural network SDN, such as figure 1 , including the following steps:

[0038]Collect and analyze the packet_in packets sent by the Openflow switch to the OpenFlow controller;

[0039] Analyze the received packet_in packet, and extract all the fields and corresponding values ​​of the packet;

[0040] Based on the principle of three-way decision-making, use the probability model of Naive B...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The present invention relates to the technical field of network security, in particular to a neural network-based SDN DDoS detection method and a detection system. The system of the present invention includes an information extraction module, an abnormal early warning module, a flow table information collection module, an information processing module and a detection module; The information extraction module is used to extract the source IP address and destination IP address information in the packet_in package; the abnormal warning module is used for the three-way decision-making principle, using the probability model of naive Bayesian to obtain the threshold of abnormal alarm, and calculate the type of data packet. If the probability is lower than the threshold, an abnormal warning is issued; the flow table information collection module is used to collect flow table data; the information processing module is used to standardize, normalize, and reduce the data operation of the collected OpenFlow flow table data; In the software-defined network, abnormal information in the network can be quickly judged and an early warning can be issued without causing too much load on the network.

Description

technical field [0001] The invention relates to the technical field of network security, in particular to a neural network-based DDoS detection method and system in an SDN network. Background technique [0002] In the era of cloud computing and big data, massive data storage and processing require high-performance servers to support, and cloud computing is actually an application after virtualizing resource pools, based on virtualization technology. Both cloud computing and virtualization require centralized control, and the three most important concepts of SDN are: programmable (open API interface), separation of control plane and data plane, and centralized control model. The SDN-based network architecture can more easily realize network virtualization, thereby providing support for services related to big data. However, Distributed Denial of Service (DDoS) has always been a key research object in the field of network security. It seriously threatens the development of ne...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06G06N3/08
CPCH04L63/1458H04L63/1416G06N3/08Y02D30/50
Inventor 尚凤军熊雄罗雪兰
Owner CHONGQING UNIV OF POSTS & TELECOMM