Font Size: a A A

The Research And Implementation Of A Network Intrusion Tracking And Response System Based On SDN Technology

Posted on:2019-07-10Degree:MasterType:Thesis
Country:ChinaCandidate:C M LiFull Text:PDF
GTID:2428330596460899Subject:Computer Science and Technology
Abstract/Summary:
With the continuous popularization of the Internet,the scale of the network has expanded dramatically,the network structure has become more and more complex,and the difficulty of network management has become more and more serious.At the same time,network security issues have become increasingly prominent.In the face of the complex and grave network security situation,traditional network security solutions are bloated and sluggish.The emergence of Software Defined Networking(SDN)technology has provided new ideas for the solution of network security problems.Based on the actual environment of CERNET(China Education and Research Network),this paper uses SDN technology to explore and verify related network security solutions,and implements a network intrusion tracking and response system based on SDN technology.The system controls the forwarding of packets through OpenFlow switches,and it can realize the collection and analysis of suspicious traffic and the automatic response to malicious traffic interception without affecting the normal network traffic.And the system has good scalability and can easily add support for new response tasks.This paper first points out the existing shortcomings of the existing HYDRA system,and then proposes research content based on the existing deficiencies of the system,and then according to the research results to improve the existing deficiencies of the system.The improved system becomes a plug-in network emergency response platform.The platform provides two functions: on the one hand,it can timely respond to network security incidents,minimize the losses caused by network attacks,and on the other hand,it can track and monitor the network malicious traffic,and find the source of the attack as far as possible.And fundamentally solve the threat of network security.The improvement of HYDRA system's architecture is the focus of this paper.First of all,a requirement analysis is made on the improvement of the system architecture,and then a corresponding solution is proposed and implemented according to the requirements analysis results.The research and function development of RYU controller is another focus of this paper.The paper first introduced the concept of the SDN controller,then introduced the RYU controller,proposed the system requirements for the controller and explained the reasons for the system to select the RYU controller,and then made some function expansion for the RYU controller according to the system requirements.The response task life cycle management of HYDRA system is the focus of this article.As a plug-in network emergency response platform,it needs to deal with different types of response task requests of different types.Therefore,a complete task management mechanism is needed to ensure that different tasks receive responses in a reasonable and orderly manner.At the end of the paper,the experimental environment of HYDRA system is introduced,and the overall function of the system and the extended function of the RYU controller are verified.The system function was verified through a case of tracking the actual response of the system.The results show that the improvement to the HYDRA system was successful.Then according to the actual response of the system,the controller's extended functions were verified.The verification results show that the modification of the RYU controller was successful.
Keywords/Search Tags:Software Defined Networking, Intrusion Tracking, Emergency Response, Task Management
Related items