CN113037731B - 基于sdn架构和蜜网的网络流量控制方法及系统 - Google Patents
基于sdn架构和蜜网的网络流量控制方法及系统 Download PDFInfo
- Publication number
- CN113037731B CN113037731B CN202110221397.7A CN202110221397A CN113037731B CN 113037731 B CN113037731 B CN 113037731B CN 202110221397 A CN202110221397 A CN 202110221397A CN 113037731 B CN113037731 B CN 113037731B
- Authority
- CN
- China
- Prior art keywords
- honey
- network
- honeypot
- module
- information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 235000012907 honey Nutrition 0.000 title claims abstract description 125
- 238000000034 method Methods 0.000 title claims abstract description 26
- 230000004044 response Effects 0.000 claims abstract description 66
- 238000012216 screening Methods 0.000 claims abstract description 30
- 238000001514 detection method Methods 0.000 claims abstract description 11
- 238000005516 engineering process Methods 0.000 claims description 7
- 238000013519 translation Methods 0.000 claims description 4
- 238000013475 authorization Methods 0.000 claims description 3
- 230000005540 biological transmission Effects 0.000 claims description 3
- 235000014510 cooky Nutrition 0.000 claims description 3
- 230000002159 abnormal effect Effects 0.000 abstract description 2
- 230000006399 behavior Effects 0.000 abstract description 2
- 238000012986 modification Methods 0.000 description 8
- 230000004048 modification Effects 0.000 description 8
- 230000003993 interaction Effects 0.000 description 5
- 238000004891 communication Methods 0.000 description 4
- 238000010586 diagram Methods 0.000 description 4
- 238000013461 design Methods 0.000 description 3
- 230000006870 function Effects 0.000 description 3
- 238000007689 inspection Methods 0.000 description 2
- 238000000926 separation method Methods 0.000 description 2
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000013481 data capture Methods 0.000 description 1
- 230000007123 defense Effects 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 238000012423 maintenance Methods 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 230000006855 networking Effects 0.000 description 1
- 230000003287 optical effect Effects 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 230000000750 progressive effect Effects 0.000 description 1
- 238000007711 solidification Methods 0.000 description 1
- 230000008023 solidification Effects 0.000 description 1
- 230000003068 static effect Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1491—Countermeasures against malicious traffic using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y02—TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
- Y02D—CLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
- Y02D30/00—Reducing energy consumption in communication networks
- Y02D30/50—Reducing energy consumption in communication networks in wire-line communication networks, e.g. low power modes or reduced link rate
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (2)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202110221397.7A CN113037731B (zh) | 2021-02-27 | 2021-02-27 | 基于sdn架构和蜜网的网络流量控制方法及系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202110221397.7A CN113037731B (zh) | 2021-02-27 | 2021-02-27 | 基于sdn架构和蜜网的网络流量控制方法及系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN113037731A CN113037731A (zh) | 2021-06-25 |
CN113037731B true CN113037731B (zh) | 2023-06-16 |
Family
ID=76464705
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202110221397.7A Active CN113037731B (zh) | 2021-02-27 | 2021-02-27 | 基于sdn架构和蜜网的网络流量控制方法及系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN113037731B (zh) |
Families Citing this family (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN113438258A (zh) * | 2021-08-27 | 2021-09-24 | 广东省新一代通信与网络创新研究院 | 一种用于UDP Flood攻击的防御方法及系统 |
CN114531270B (zh) * | 2021-12-31 | 2023-11-03 | 网络通信与安全紫金山实验室 | 针对分段路由标签探测的防御方法及装置 |
CN114666096A (zh) * | 2022-02-24 | 2022-06-24 | 中国人民解放军国防科技大学 | 一种基于动态服务链的智能蜜网系统及其实现方法 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2017064554A1 (en) * | 2015-10-13 | 2017-04-20 | Schneider Electric Industries Sas | Method for arranging workloads in a software defined automation system |
CN109246108A (zh) * | 2018-09-18 | 2019-01-18 | 中国人民解放军战略支援部队信息工程大学 | 拟态化蜜罐指纹混淆系统、方法及其sdn网络架构 |
CN109716732A (zh) * | 2016-08-03 | 2019-05-03 | 施耐德电器工业公司 | 用于软件定义的自动化系统中的部署的工业软件定义的网络架构 |
CN111885067A (zh) * | 2020-07-28 | 2020-11-03 | 福建奇点时空数字科技有限公司 | 一种面向流量的集成式蜜罐威胁数据捕获方法 |
Family Cites Families (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104506507B (zh) * | 2014-12-15 | 2017-10-10 | 蓝盾信息安全技术股份有限公司 | 一种sdn网络的蜜网安全防护系统及方法 |
KR102155262B1 (ko) * | 2017-09-11 | 2020-09-11 | 숭실대학교산학협력단 | 탄력적 허니넷 시스템 및 그 동작 방법 |
KR101917062B1 (ko) * | 2017-11-02 | 2018-11-09 | 한국과학기술원 | 소프트웨어 정의 네트워크에서 링크 플러딩 공격을 완화하기 위한 허니넷 방법, 시스템 및 컴퓨터 프로그램 |
CN111818077A (zh) * | 2020-07-21 | 2020-10-23 | 北方工业大学 | 一种基于sdn技术的工控混合蜜罐系统 |
CN112118577B (zh) * | 2020-09-18 | 2023-10-13 | 国网山东省电力公司青岛供电公司 | 基于SDN虚拟蜜罐的IoT网络攻击消减系统及方法 |
-
2021
- 2021-02-27 CN CN202110221397.7A patent/CN113037731B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2017064554A1 (en) * | 2015-10-13 | 2017-04-20 | Schneider Electric Industries Sas | Method for arranging workloads in a software defined automation system |
CN109716732A (zh) * | 2016-08-03 | 2019-05-03 | 施耐德电器工业公司 | 用于软件定义的自动化系统中的部署的工业软件定义的网络架构 |
CN109246108A (zh) * | 2018-09-18 | 2019-01-18 | 中国人民解放军战略支援部队信息工程大学 | 拟态化蜜罐指纹混淆系统、方法及其sdn网络架构 |
CN111885067A (zh) * | 2020-07-28 | 2020-11-03 | 福建奇点时空数字科技有限公司 | 一种面向流量的集成式蜜罐威胁数据捕获方法 |
Non-Patent Citations (1)
Title |
---|
基于深度学习的SDN虚拟蜜网路由优化;胡洋;;计算机系统应用(第10期);全文 * |
Also Published As
Publication number | Publication date |
---|---|
CN113037731A (zh) | 2021-06-25 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US9825990B2 (en) | System and method for software defined behavioral DDoS attack mitigation | |
Ioannidis et al. | Implementing pushback: Router-based defense against DDoS attacks | |
Dabbagh et al. | Software-defined networking security: pros and cons | |
CN108063765B (zh) | 适于解决网络安全的sdn系统 | |
Giotis et al. | Combining OpenFlow and sFlow for an effective and scalable anomaly detection and mitigation mechanism on SDN environments | |
US8484372B1 (en) | Distributed filtering for networks | |
Abliz | Internet denial of service attacks and defense mechanisms | |
US8474041B2 (en) | Autonomous diagnosis and mitigation of network anomalies | |
CN113037731B (zh) | 基于sdn架构和蜜网的网络流量控制方法及系统 | |
CN110830469A (zh) | 基于SDN和BGP流程规范的DDoS攻击防护系统及方法 | |
US11546266B2 (en) | Correlating discarded network traffic with network policy events through augmented flow | |
Wang et al. | Towards mitigating link flooding attack via incremental SDN deployment | |
Rengaraju et al. | Detection and prevention of DoS attacks in Software-Defined Cloud networks | |
CN112202646B (zh) | 一种流量分析方法和系统 | |
Polat et al. | The effects of DoS attacks on ODL and POX SDN controllers | |
US8964763B2 (en) | Inter-router communication method and module | |
Gkounis | Cross-domain DoS link-flooding attack detection and mitigation using SDN principles | |
Gautam et al. | Experimental security analysis of SDN network by using packet sniffing and spoofing technique on POX and Ryu controller | |
Arins | Firewall as a service in SDN OpenFlow network | |
JP5178573B2 (ja) | 通信システムおよび通信方法 | |
JP2013070325A (ja) | 通信システム、通信装置、サーバ、通信方法 | |
Chen et al. | Policy management for network-based intrusion detection and prevention | |
JP2008219149A (ja) | トラヒック制御システムおよびトラヒック制御方法 | |
TWI797962B (zh) | 基於SASE的IPv6雲邊緣網路安全連線方法 | |
KR101060615B1 (ko) | 올아이피네트워크 환경의 공격 탐지 및 추적 시스템 및 방법 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CP03 | Change of name, title or address |
Address after: 450000 Science Avenue 62, Zhengzhou High-tech Zone, Henan Province Patentee after: Information Engineering University of the Chinese People's Liberation Army Cyberspace Force Country or region after: China Patentee after: Purple Mountain Laboratories Address before: No. 62 Science Avenue, High tech Zone, Zhengzhou City, Henan Province Patentee before: Information Engineering University of Strategic Support Force,PLA Country or region before: China Patentee before: Purple Mountain Laboratories |
|
CP03 | Change of name, title or address |
Address after: No. 62 Science Avenue, High tech Zone, Zhengzhou City, Henan Province Patentee after: Information Engineering University of Strategic Support Force,PLA Country or region after: China Patentee after: Zijinshan Laboratory Address before: No. 62 Science Avenue, High tech Zone, Zhengzhou City, Henan Province Patentee before: Information Engineering University of Strategic Support Force,PLA Country or region before: China Patentee before: Purple Mountain Laboratories |