Netinfo Security ›› 2016, Vol. 16 ›› Issue (3): 71-76.doi: 10.3969/j.issn.1671-1122.2016.03.012

• Orginal Article • Previous Articles     Next Articles

Troubleshooting Based on Packet Traceback in Software-defined Networks

Kuan JIANG(), Peng YANG   

  1. Nangjing University of Posts and Telecommunications, Nanjing Jiangsu 210000, China
  • Received:2015-12-15 Online:2016-03-25 Published:2020-05-13

Abstract:

With the increasingly numbers of serious problems of network security, network operators solve specific problems mainly use the tools such as ping, traceroute, SNMP, tcpdump and so on. Their experience and ability is crucial to find the position of the fault. This paper describes the troubleshooting way based on provenance traceback and improves it with packets traceback. Provenance traceback is used in detection of rule conflicts, which using graph theory to locate the root cause, but not used widely in the detection of rule loss. This paper presents a troubleshooting solution that based on packet traceback, which can effectively detect the rule conflicts and rules loss and expand the scope, which is an important complement to the provenance traceback. Constructing packets by specific source IP addresses, using back policy to get the fault location. The whole process does not require the user to back human intervention, with real-time and automated features.

Key words: software-defined networks, provenance traceback, troubleshooting

CLC Number: