Toggle navigation
Home
About
About Journal
Historical Evolution
Indexed In
Awards
Reference Index
Editorial Board
Journal Online
Archive
Project Articles
Most Download Articles
Most Read Articles
Instruction
Contribution Column
Author Guidelines
Template
FAQ
Copyright Agreement
Expenses
Academic Integrity
Contact
Contact Us
Location Map
Subscription
Advertisement
中文
Journals
Publication Years
Keywords
Search within results
(((LIU Ze[Author]) AND 1[Journal]) AND year[Order])
AND
OR
NOT
Title
Author
Institution
Keyword
Abstract
PACS
DOI
Please wait a minute...
For Selected:
Download Citations
EndNote
Ris
BibTeX
Toggle Thumbnails
Select
Software defined network path security based on Hash chain
LI Zhaobin, LIU Zeyi, WEI Zhanzhen, HAN Yu
Journal of Computer Applications 2019, 39 (
5
): 1368-1373. DOI:
10.11772/j.issn.1001-9081.2018091857
Abstract
(
743
)
PDF
(1058KB)(
511
)
Knowledge map
Save
For the security problem that the SDN (Software Defined Network) controller can not guarantee the network strategy issued by itself to be correctly executed on the forwarding devices, a new forwarding path monitoring security solution was proposed. Firstly, based on the overall view capability of the controller, a path credential interaction processing mechanism based on OpenFlow was designed. Secondly, Hash chain and message authentication code were introduced as the key technologies for generating and processing the forwarding path credential information. Thirdly, on this basis, Ryu controller and Open vSwitch open-source switch were deeply optimized,with credential processing flow added, constructing a lightweight path security mechanism. The test results show that the proposed mechanism can effectively guarantee the security of data forwarding path, and its throughput consumption is reduced by more than 20% compared with SDNsec, which means it is more suitable for the network environment with complex routes, but its fluctuates of latency and CPU usage are more than 15%, which needs further optimization.
Reference
|
Related Articles
|
Metrics
Select
Application-layer DDoS defense model based on Web behavior trajectory
LIU Zeyu, XIA Yang, ZHANG Yilong, REN Yuan
Journal of Computer Applications 2017, 37 (
1
): 128-133. DOI:
10.11772/j.issn.1001-9081.2017.01.0128
Abstract
(
841
)
PDF
(949KB)(
644
)
Knowledge map
Save
To defense application-layer Distributed Denial of Service (DDoS) built on the normal network layer, a defense model based on Web behavior trajectory in the Web application server was constructed. User's access behavior was abstracted into Web behavior trajectory, and according to the generation approach about attack request as well as behavior characteristics of user access to Web pages, four kinds of suspicion were defined, including access dependency suspicion, behavior rate suspicion, trajectory similarity suspicion, and trajectory deviation suspicion. The deviation values between normal sessions and attack sessions were calculated to detect the application-layer DDoS to a specific website. The defense model prohibited the user access from DDoS when detecting the attack request generated by the user. In the experiment, real data was acted as the training set. Then, through simulating different kinds of attack request, the defense model could identify the attack request and take the defense mechanism against the attack. The experimental results demonstrate that the model can detect and defense the application-layer DDoS to a specific website.
Reference
|
Related Articles
|
Metrics
Select
Construction of sentiment polarity dataset for image evaluation of foreign educational aid#br#
#br#
ZHOU Huiwei, LI Henglin, YAO Weihong, LIU Ze
Journal of Computer Applications DOI:
10.11772/j.issn.1001-9081.2026030359
Online available: 07 August 2026