信息通信技术与政策

信息通信技术与政策

信息通信技术与政策 ›› 2025, Vol. 51 ›› Issue (1): 56-63.doi: 10.12267/j.issn.2096-5931.2025.01.009

专题:网络安全 上一篇    下一篇

软件定义网络DDoS攻击问题研究

Research on DDoS attack in SDN

张健1, 朱丹2   

  1. 1.中国信息通信研究院安全研究所,北京 100191
    2.中国信息通信研究院无线电研究中心,北京 100191
  • 收稿日期:2024-06-28 出版日期:2025-01-25 发布日期:2025-02-14
  • 通讯作者: 朱丹, 中国信息通信研究院无线电研究中心工程师,主要从事5G技术与发展、智慧农业政策与规划、数字经济发展与规划等方面的研究工作
  • 作者简介:
    张健, 中国信息通信研究院安全研究所高级工程师,博士,主要从事信息通信技术、政策、标准等方面的研究工作

ZHANG Jian1, ZHU Dan2   

  1. 1. Security Research Institute, China Academy of Information and Communications Technology, Beijing 100191, China
    2. Research Center for Radio Management, China Academy of Information and Communications Technology, Beijing 100191, China
  • Received:2024-06-28 Online:2025-01-25 Published:2025-02-14

摘要:

作为一种新的网络体系架构,SDN已经得到业界广泛认可并被大规模应用和部署,但其本身却因集中控制等体系架构方面的原因成为DDoS攻击的主要目标,对SDN及有关应用造成较大危害。以SDN中的DDoS攻击问题为研究对象,首先总结了SDN体系架构存在的DDoS攻击潜在风险,分析了现阶段SDN所主要面临的DDoS攻击形式;其次,介绍了目前业界检测和防御DDoS攻击的主要解决方案,探讨了当前DDoS攻击检测和防御研究中主要存在的问题;最后,对下一步有关研究工作进行了展望。

关键词: 软件定义网络, 分布式拒绝服务, OpenFlow, 统计分析, 机器学习

Abstract:

As a new network architecture, SDN has been widely recognized in the industry and widely applied and deployed on a large scale. However, SDN has become the main target of DDoS attacks due to its centralized control mode, causing significant harm to SDN networks and related applications. This paper takes DDoS attacks in SDN as the research object. Firstly, the potential risks of DDoS attacks in SDN network architecture are summarized and the main forms of DDoS attacks faced by SDN at present are analyzed. Then, the main solutions for detecting and defending against DDoS attacks in the industry are introduced and the main problems in current research on DDoS attacks are discussed. Finally, the future research work of DDoS attack in SDN is discussed.

Key words: SDN, DDoS, OpenFlow, statistical analysis, machine learning

中图分类号: