FIELD: active protection devices.
SUBSTANCE: invention relates to a method and a device for detecting a malicious attack. Method includes: receiving, by a controller, a packet-in message sent by a first switch, comprising source host identifier and a destination host identifier of a data packet for which the first switch does not find a flow entry; when determining that a host indicated by the destination host identifier does not exist in an SDN network, sending an abnormal flow entry, which includes the source host identifier, to the first switch; receiving a triggering count from the first switch after the abnormal flow entry times out, the triggering count indicating the number of times that the abnormal flow entry is triggered; determining according to the triggering count, whether a malicious attack is initiated from a source host indicated by the source host identifier.
EFFECT: technical result consists in detecting a malicious attack from a host device with a reduction in the amount of data processing by the software defined networking (SDN) network and improving its performance.
23 cl, 14 dwg, 2 tbl
Title | Year | Author | Number |
---|---|---|---|
FLOW TABLE MANAGEMENT METHOD AND RELEVANT DEVICE AND SYSTEM | 2014 |
|
RU2668065C2 |
METHOD OF MULTI-ADDRESS BROADCASTING, APPARATUS AND SYSTEM FOR PROGRAM-CONFIGURABLE NETWORK | 2014 |
|
RU2645280C1 |
CENTRALIZED CONTROL OF SOFTWARE-DEFINED AUTOMATED SYSTEM | 2016 |
|
RU2747966C2 |
SOFTWARE-DEFINED AUTOMATED SYSTEM AND ARCHITECTURE | 2016 |
|
RU2729885C2 |
METHOD, APPARATUS AND EQUIPMENT FOR TRANSMITTING DATA AND READABLE DATA MEDIUM | 2018 |
|
RU2742542C1 |
MULTI-SIGNAL ANALYSIS FOR IDENTIFICATION OF A COMPROMISED APPLICATION AREA | 2018 |
|
RU2768562C2 |
ARP PROCESSING METHOD, SWITCH DEVICE AND CONTROL MODULE | 2014 |
|
RU2661768C2 |
SDN-CONTROLLER, DATA PROCESSING CENTER SYSTEM AND THE ROUTED CONNECTION METHOD | 2014 |
|
RU2651149C2 |
METHOD AND DEVICE FOR AUTOMATIC CONTROL OF VIRTUALIZED FLOW MIRRORING POLICY AND DATA MEDIUM | 2018 |
|
RU2729406C1 |
PROTECTIVE INFRASTRUCTURE AND METHOD FOR PEER NAME RESOLUTION PROTOCOL (PNRP) | 2003 |
|
RU2320008C2 |
Authors
Dates
2018-03-16—Published
2014-09-05—Filed