Netinfo Security ›› 2022, Vol. 22 ›› Issue (2): 76-85.doi: 10.3969/j.issn.1671-1122.2022.02.009

Previous Articles     Next Articles

Dynamic Hopping Technology of Double Virtual IP Address for SDN Data Layer

HU Ruiqin1,2(), TAN Jinglei1,2, PENG Xinhe3, ZHANG Hongqi1,2   

  1. 1. Department of Cryptogram Engineering, Information Engineering University, Zhengzhou 450001, China
    2. Henan Key Laboratory of Information Security, Zhengzhou 450001, China
    3. School of Economics and Management, Yan’an University, Yan’an 716000, China
  • Received:2021-09-15 Online:2022-02-10 Published:2022-02-16
  • Contact: HU Ruiqin E-mail:zero_hrq@163.com

Abstract:

Sniffing attack is a common and highly concealed network attack, and it poses a serious threat to the confidentiality of communication data. However, the traditional defense means are limited by the serious asymmetry of the network offensive and defensive countermeasures, and it is difficult to deal with this threat effectively. The dynamic hopping technology of double bogus IP address for SDN data layer was proposed. Firstly, the double bogus IP address was used to destroy the spatial correlation of communication data. Secondly, the correlation of communication data was destroyed in time dimension by periodic IP address hopping, to increase the level and cost of sniffing the attacker’s recombination of communication data. The analysis of anti-attack effectiveness and simulation experiments results show that the technology can improve the ability of anti-sniffing attack, and it can also ensure the lower CPU consumption and communication delay.

Key words: sniffing attack, moving target defense, IP hopping, SDN

CLC Number: