Extending the Floodlight Controller

Laura Victoria Morales Medina, Andrés Felipe Murillo-Piedrahita, S. Rueda
{"title":"Extending the Floodlight Controller","authors":"Laura Victoria Morales Medina, Andrés Felipe Murillo-Piedrahita, S. Rueda","doi":"10.1109/NCA.2015.11","DOIUrl":null,"url":null,"abstract":"Software Defined Networking (SDN) emerges as an option to implement security features difficult to develop and deploy in traditional network infrastructures. SDN has a programmable component that can build a global view of the actual state of a network and change network configuration to react to actual events: a controller. Additionally, a controller's functionality may be extended to meet specific requirements. This work studies the features that Floodlight, a Java based SDN controller, offers to extend its behavior. Previous works have studied Floodlight architecture and performance, but not these features. To meet the goal, we selected a known security context for traditional networks: DDoS detection and mitigation. This paper presents design and implementation of the CDM(Collection, Detection, and Mitigation) module, a statistical-based DDoS detection module that extends Floodlight. Statistical algorithms are a good fit for SDN, they have low memory and CPU demands, and can react to changes in network configuration. The module also uses Java features to establish an interface for statistical-based detection algorithms, enabling administrators to use libraries of algorithms and select some of them according to their systems. The results show that Floodlight is easy to extend and flexible. It is also efficient regarding CPU, but requires more memory than other controllers. The collection, detection, and mitigation algorithms run fast, although the time window required to detect statistical change bounds reaction times.","PeriodicalId":222162,"journal":{"name":"2015 IEEE 14th International Symposium on Network Computing and Applications","volume":"283 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-09-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"30","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 IEEE 14th International Symposium on Network Computing and Applications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NCA.2015.11","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 30

Abstract

Software Defined Networking (SDN) emerges as an option to implement security features difficult to develop and deploy in traditional network infrastructures. SDN has a programmable component that can build a global view of the actual state of a network and change network configuration to react to actual events: a controller. Additionally, a controller's functionality may be extended to meet specific requirements. This work studies the features that Floodlight, a Java based SDN controller, offers to extend its behavior. Previous works have studied Floodlight architecture and performance, but not these features. To meet the goal, we selected a known security context for traditional networks: DDoS detection and mitigation. This paper presents design and implementation of the CDM(Collection, Detection, and Mitigation) module, a statistical-based DDoS detection module that extends Floodlight. Statistical algorithms are a good fit for SDN, they have low memory and CPU demands, and can react to changes in network configuration. The module also uses Java features to establish an interface for statistical-based detection algorithms, enabling administrators to use libraries of algorithms and select some of them according to their systems. The results show that Floodlight is easy to extend and flexible. It is also efficient regarding CPU, but requires more memory than other controllers. The collection, detection, and mitigation algorithms run fast, although the time window required to detect statistical change bounds reaction times.
扩展泛光灯控制器
软件定义网络(SDN)作为实现难以在传统网络基础设施中开发和部署的安全特性的一种选择而出现。SDN有一个可编程组件,它可以构建网络实际状态的全局视图,并更改网络配置以对实际事件做出反应:控制器。此外,控制器的功能可以扩展以满足特定的要求。本文研究了基于Java的SDN控制器Floodlight提供的扩展其行为的特性。以前的作品研究了泛光灯的建筑和性能,但没有研究这些特征。为了实现这一目标,我们为传统网络选择了一个已知的安全环境:DDoS检测和缓解。本文介绍了基于统计的DDoS检测模块CDM(收集、检测和缓解)模块的设计和实现,该模块扩展了泛光灯。统计算法非常适合SDN,它们具有较低的内存和CPU需求,并且可以对网络配置的变化做出反应。该模块还利用Java特性建立了基于统计的检测算法接口,使管理员能够使用算法库,并根据自己的系统选择其中的一些算法。结果表明,该泛光灯易于扩展,具有一定的灵活性。它在CPU方面也很高效,但需要比其他控制器更多的内存。尽管检测统计变化所需的时间窗口限制了反应时间,但收集、检测和缓解算法运行速度很快。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信