| SDN network takes the control plane as the core of the whole network architecture,centrally maintains the topology structure,routing strategy and other information of the network,and generates a flow table according to the network state and strategy,and sends it to the data plane for matching,so as to realize the effective management and control of the network.The feature of controlling forwarding separation also brings a series of security problems,which makes the SDN control plane more vulnerable to DDoS attacks.With the development of the Internet,the problems of semantic overload and security risks brought by single IP addressing are gradually exposed.In order to break through the bottleneck of IP addressing,the research on multi-modal routing addressing technology is constantly improving and developing,but there is still a gap in this field.In order to realize the endogenous security mechanism in SDN network,aiming at the above problems in SDN network environment,this paper proposes a combined SDN security mechanism based on multidimensional addressing and fusion DDoS attack detection.Using P4 language to realize programmable data plane,custom multimod head on the data plane implementation multimodal addressing and routing mechanism,make the IP identification,content identification,identity identification,geographical space identification of a variety of modal identification can coexist in the network,P4 switch can identify different modal identification information and corresponding operation,complete the static defense mechanism in SDN network endogenous security construction.The transmission delay of the data with the custom multimodal header in the network is maintained at a low level,and there is no obvious gap with the addressing delay based on IP identification.The performance of the multimodal routing addressing mechanism based on P4 custom extended header is verified.At the same time for SDN network puts forward a kind of condition based on the source/purpose of IP entropy and improve the combination of DNN model of DDoS attack detection mechanism,set the condition entropy threshold for network traffic filtering,filtering that suspicious traffic by adding the depth of the residual module neural network for further detection,on the premise of ensuring accuracy as far as possible,complete the dynamic defense mechanism of SDN network endogenous security.Compared with other DDoS attack detection algorithms,the proposed algorithm has higher accuracy and lower false alarm rate,and also higher detection efficiency.The experimental results show that the research results of this paper have a positive influence on constructing the dynamic and static combination security mechanism based on SDN network and realizing the endogenous security of SDN network. |