信息安全研究 ›› 2022, Vol. 8 ›› Issue (2): 135-.

• 学术论文 • 上一篇    下一篇

可编程数据平面系统异常检测系统的设计与实现

陈立军,张屹,陈孝如   

  1. 广州大学华软软件学院(广州软件学院),广东 广州 510990 
  • 出版日期:2022-02-05 发布日期:2022-01-23
  • 通讯作者: 陈立军(1974-),男(苗族),广西桂林人,讲师,研究生,主要从事电子对抗技术,E-mail:372158286@qq.com
  • 作者简介: 陈立军(1974-),男(苗族),广西桂林人,讲师,研究生,主要从事电子对抗技术,E-mail:372158286@qq.com 张屹(1972-),男(汉族),北京人,教授,博士,主要从事电子对抗技术E-mail:zy@mail.seig.edu.cn 陈孝如,(1975- ),男,河南漯河人,CCF会员,副教授,研究方向,神经网络, E-mail:cxr@mail.seig.edu.cn

Design and Implementation of Anomaly Detection System for Programmable Data Plane System

  • Online:2022-02-05 Published:2022-01-23

摘要: 可编程数据平面为实现快速、准确和数据驱动的控制回路决策提供了令人兴奋的机会,很多研究者已经提出了许多数据平面系统来实时地处理网络动态(例如,拥塞、故障),这些系统的核心是具有数据包处理的数据平面算法,可连续监控流量并自动响应。尽管有诸多好处,但对网络事件的自动响应会导致潜在输入源的增加,从而增加了攻击面。本文设计了一个异常检测系统,用于在运行时检测此类攻击,系统对合理的预期行为进行建模,并使用该模型作为参考来检查系统是否受到攻击,实验证明:所提议的异常检测系统在对抗性攻防方面是可行性的,也是有效的。

关键词: 可编程数据平面, 网络攻击, 网络监控, 安全与隐私, 入侵检测系统, 拒绝服务攻击

Abstract: Programmable data plane to achieve rapid and accurate decision-making and data-driven control circuit provides exciting opportunities, many researchers have proposed many graphic system to real-time processing network dynamic data (for example, congestion, fault), the core of these systems is a data plane algorithm with packet processing, can be continuous automatic monitoring traffic and response. Despite its benefits, automatic response to network events increases the attack surface by increasing potential input sources. In this paper, an anomaly detection system is designed to detect such attacks at runtime. The system models the reasonable expected behavior and uses the model as a reference to check whether the system is attacked or not. Experiments show that the proposed anomaly detection system is feasible and effective in antagonistic attack and defense.

Key words: Programmable data plane, Network attack, Network monitoring, Security and privacy, Intrusion detection system, Denial of service attack