透過您的圖書館登入
IP:3.15.197.123
  • 學位論文

運用SDN強化入侵防護安全機制

Employing software-defined Network to strengthen the intrusion prevention security mechanism

指導教授 : 梁德昭

摘要


現代人的生活已離不開網路,因此,網路的安全性也漸漸的受到大家的重視。如何能更有效的防範有心人的惡意攻擊,減少網路攻擊帶來的損失,是許多人一直努力想解決的問題。傳統網路仰賴入侵偵測系統來檢測是否有惡意攻擊,然而入侵偵測系統卻無法很完善的阻擋這些惡意人士造成的網路攻擊。 為了改善傳統網路無法有效率抵禦惡意攻擊的缺點,本文嘗試運用軟體定義網路(SDN)結合入侵偵測系統的警告機制,透過集中管理交換機,結合流表 (Flow Table) 的設定,達到過濾並阻擋封包的效果,強化傳統阻擋入侵的安全機制,也能有效的減少頻寬消耗,維護整體網路的安全性。

並列摘要


Modern life cannot be separated from the Internet,as a result, the security of the Internet has gradually become more and more important to everyone. How to more effectively prevent malicious attacks from malicious people and reduce the losses caused by cyber attacks is a problem that many people have been trying hard to solve. Traditional networks rely on intrusion detection systems to detect malicious attacks. However, intrusion detection systems cannot adequately block the network attacks caused by these malicious individuals. In order to improve the shortcomings of traditional networks that cannot be effective against malicious attacks. This article attempts to use software-defined networking (SDN) to incorporate the alert mechanism of intrusion detection systems. Through the centralized management of switches, combined with the setting of the Flow Table, to filter and block packets, strengthening traditional security mechanisms that block intrusions can also effectively reduce bandwidth consumption and maintain overall network security.

並列關鍵字

SDN OpenFlow IDS Mininet OpenDaylight

參考文獻


[1]OpenDaylight https://www.opendaylight.org/
[2]OpenFlow principle http://www.xinguard.com/content.aspx?id=15
[3]OpenFlow Definition http://yuba.stanford.edu/cs244wiki/index.php/Overview
[4]OpenFlow Comparison mechanism http://www.netadmin.com.tw/article_content.aspx?sn=1610070003&jump=1
[5]Open Networking Foundation OpenFlow Switch Specification , Version 1.3.1 (Wire Protocol 0x04) September 6, 2012

延伸閱讀