考虑基于SDN架构的网络环境,并针对当前检测隐藏端口的方法的不足,提出一种全新的基于SDN架构的隐藏端口检测方法.利用SDN集中控制的特性,通过内存映射流表项的方法来实时提取主机的连接信息,并结合主机代理的信息进行交叉视图检测,同时在检测过程中引入检测状态机,使得准确检测出部署环境下所有主机的隐藏端口.实验结果表明,该方法能高效地检测主机恶意程序隐藏的端口,并具有良好的兼容性和系统性能.
This paper proposes a method of hidden-ports detection based on SDN, with the characteristics of controlling the whole network, the controller could retrieve all the sessions' information, combined with the customized data received from proxy, the controller could find all the sessions from hidden-ports based on the crossview of full information and visible information. As the experiment shows, this method could detect all the hidden-ports effectively and compatibly.