RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    링 토폴로지를 사용하는 SDN 환경에서 주기적 임의 링 재구성을 통한 침해 스위치 공격 대응

    한글로보기

    https://www.riss.kr/link?id=T17549108

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    본 연구는 산업 제어 시스템(ICS)을 위한 링 토폴로지 SDN 배포에서 손상된 스위치, 특히 스푸핑 기반 중간자(MITM) 공격으로 인한 지속적인 위협을 다룹니다. 우리는 주기적인 랜덤 링 재구성을 제안하며, 이 과정에서 컨트롤러는 인덱스가 참조하는 사전 정의된 공유 링 시퀀스 세트를 유지하면서 정책 테이블-VLAN 매핑을 통해 사전 설치된 흐름을 한 번에 활성화합니다. 이 설계는 (i) 공격자의 관찰/조작 창을 단축시켜 MITM 지속성을 줄입니다; (ⅱ) 일관된 재구성 정책을 유지하지 않는 손상된 스위치는 자연스럽게 제외됩니다; (ⅲ) 확장성을 유지하여 장치 추가 또는 교체 시 보안 및 운영 정책의 동시 진화를 가능하게 합니다. 우리는 Open vSwitch와 OpenDaylight가 포함된 Mininet을 배포하여 시뮬레이션 환경을 구축하고, Mosquitto를 사용하여 랜덤 MQTT 트래픽을 생성합니다. 우리는 손상된 스위치가 정상 스위치를 스푸핑하고 스니프 공격을 수행하는 MITM 사례를 시뮬레이션합니다. 제안된 절차는 손상된 스위치를 주기적으로 경로 발판에서 박탈하여 손상된 요소를 링에서 제외하고, 정상 노드와 링을 재구성하여 통신을 유지할 수 있습니다. 결과는 링 토폴로지의 고유한 운영 이점을 희생하지 않으면서 손상된 스위치 공격의 위험을 낮추는 실용적인 방어 방법을 보여줍니다.
    번역하기

    본 연구는 산업 제어 시스템(ICS)을 위한 링 토폴로지 SDN 배포에서 손상된 스위치, 특히 스푸핑 기반 중간자(MITM) 공격으로 인한 지속적인 위협을 다룹니다. 우리는 주기적인 랜덤 링 재구성을...

    본 연구는 산업 제어 시스템(ICS)을 위한 링 토폴로지 SDN 배포에서 손상된 스위치, 특히 스푸핑 기반 중간자(MITM) 공격으로 인한 지속적인 위협을 다룹니다. 우리는 주기적인 랜덤 링 재구성을 제안하며, 이 과정에서 컨트롤러는 인덱스가 참조하는 사전 정의된 공유 링 시퀀스 세트를 유지하면서 정책 테이블-VLAN 매핑을 통해 사전 설치된 흐름을 한 번에 활성화합니다. 이 설계는 (i) 공격자의 관찰/조작 창을 단축시켜 MITM 지속성을 줄입니다; (ⅱ) 일관된 재구성 정책을 유지하지 않는 손상된 스위치는 자연스럽게 제외됩니다; (ⅲ) 확장성을 유지하여 장치 추가 또는 교체 시 보안 및 운영 정책의 동시 진화를 가능하게 합니다. 우리는 Open vSwitch와 OpenDaylight가 포함된 Mininet을 배포하여 시뮬레이션 환경을 구축하고, Mosquitto를 사용하여 랜덤 MQTT 트래픽을 생성합니다. 우리는 손상된 스위치가 정상 스위치를 스푸핑하고 스니프 공격을 수행하는 MITM 사례를 시뮬레이션합니다. 제안된 절차는 손상된 스위치를 주기적으로 경로 발판에서 박탈하여 손상된 요소를 링에서 제외하고, 정상 노드와 링을 재구성하여 통신을 유지할 수 있습니다. 결과는 링 토폴로지의 고유한 운영 이점을 희생하지 않으면서 손상된 스위치 공격의 위험을 낮추는 실용적인 방어 방법을 보여줍니다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    This study addresses persistent threats posed by compromised switches - particularly spoofing-based Man-In-The Middle(MITM) attacks - in ring topology SDN(Software Defined Network) deployments for Industrial Control Systems(ICS). We propose periodic random ring reconstruction, in which the controller maintains a pre-defined, shared set of ring sequences referenced by index, while switches perform one-shot activation of pre-installed flows via a policy table-VLAN(Virtual Local Area Network) mapping. This design (i) shortens the attacker’s observation/manipulation window, reducing MITM persistence; (ⅱ) naturally excludes compromised switches that do not hold a consistent reconstruction policy; (ⅲ) preserves scalability, enabling concurrent evolution of security and operational policies during device additions or replacements. We deploy Mininet with Open vSwitch and OpenDaylight to build a simulation environment and Mosquitto to generate a random MQTT(Message Queuing Telemetry Transport) traffic. We simulate a MITM case where a compromised switch spoofs a normal switch, and performs sniff attack. The proposed procedure periodically deprives the compromised switch of the path foothold, thereby can excludes the compromised element from the ring, and re-forming the ring with the normal nodes to sustain communications. The results demonstrate a practical defense that lowers the risk of compromised switch attacks without sacrificing the inherent operational benefits of ring topologies.
    번역하기

    This study addresses persistent threats posed by compromised switches - particularly spoofing-based Man-In-The Middle(MITM) attacks - in ring topology SDN(Software Defined Network) deployments for Industrial Control Systems(ICS). We propose periodic r...

    This study addresses persistent threats posed by compromised switches - particularly spoofing-based Man-In-The Middle(MITM) attacks - in ring topology SDN(Software Defined Network) deployments for Industrial Control Systems(ICS). We propose periodic random ring reconstruction, in which the controller maintains a pre-defined, shared set of ring sequences referenced by index, while switches perform one-shot activation of pre-installed flows via a policy table-VLAN(Virtual Local Area Network) mapping. This design (i) shortens the attacker’s observation/manipulation window, reducing MITM persistence; (ⅱ) naturally excludes compromised switches that do not hold a consistent reconstruction policy; (ⅲ) preserves scalability, enabling concurrent evolution of security and operational policies during device additions or replacements. We deploy Mininet with Open vSwitch and OpenDaylight to build a simulation environment and Mosquitto to generate a random MQTT(Message Queuing Telemetry Transport) traffic. We simulate a MITM case where a compromised switch spoofs a normal switch, and performs sniff attack. The proposed procedure periodically deprives the compromised switch of the path foothold, thereby can excludes the compromised element from the ring, and re-forming the ring with the normal nodes to sustain communications. The results demonstrate a practical defense that lowers the risk of compromised switch attacks without sacrificing the inherent operational benefits of ring topologies.

    더보기

    목차 (Table of Contents)

    • Ⅰ. 서 론 1
    • Ⅱ. 관련 연구 5
    • Ⅲ. SDN 환경에서의 보안 문제 7
    • Ⅳ. 시뮬레이션 결과 12
    • Ⅴ. 결 론 20
    • Ⅰ. 서 론 1
    • Ⅱ. 관련 연구 5
    • Ⅲ. SDN 환경에서의 보안 문제 7
    • Ⅳ. 시뮬레이션 결과 12
    • Ⅴ. 결 론 20
    • 참고문헌 23
    • 영문초록(Abstract) 26
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼