A comprehensive survey on DDoS detection, mitigation, and defense strategies in software-defined networks

被引:6
作者
Jain, Ankit Kumar [1 ]
Shukla, Hariom [1 ]
Goel, Diksha [2 ]
机构
[1] Natl Inst Technol Kurukshetra, Kurukshetra, India
[2] CSIROs Data61, Melbourne, Vic, Australia
来源
CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS | 2024年 / 27卷 / 09期
关键词
Software defined network; Distributed denial of service attack; Machine learning; Honeypot; Blockchain; ATTACK DETECTION; SDN; MACHINE; HONEYPOT;
D O I
10.1007/s10586-024-04596-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) has become increasingly prevalent in cloud computing, Internet of Things (IoT), and various environments to optimize network efficiency. While it provides a flexible network infrastructure, it also faces security threats, particularly from Distributed Denial of Service (DDoS) attacks due to its centralized design. This survey comprehensively reviews the efforts of various researchers in safeguarding SDN against DDoS attacks and analyzes different detection and mitigation strategies employed in SDN environments. Furthermore, the survey explores various types of DDoS attacks that can occur across different planes and communication links in SDN. Additionally, emerging security measures for preventing DDoS attacks in SDN are examined. The survey also reviews the datasets, tools, and simulators used for detecting DDoS attacks in SDN. Moreover, the survey identifies various open challenges in detecting and mitigating DDoS attacks in SDN and outlines potential future research directions. Lastly, the survey provides a comprehensive comparative analysis of various DDoS detection techniques based on various essential parameters.
引用
收藏
页码:13129 / 13164
页数:36
相关论文
共 116 条
[21]   A Comprehensive Survey of In-Band Control in SDN: Challenges and Opportunities [J].
Carrascal, David ;
Rojas, Elisa ;
Arco, Jose M. ;
Lopez-Pajares, Diego ;
Alvarez-Horcajo, Joaquin ;
Carral, Juan Antonio .
ELECTRONICS, 2023, 12 (06)
[22]   FlexProtect: A SDN-based DDoS Attack Protection Architecture for Multi-tenant Data Centers [J].
Chen, Ming-Hung ;
Ciou, Jyun-Yan ;
Chung, I-Hsin ;
Chou, Cheng-Fu .
PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING IN ASIA-PACIFIC REGION (HPC ASIA 2018), 2018, :202-209
[23]   Machine learning based low-rate DDoS attack detection for SDN enabled IoT networks [J].
Cheng, Haosu ;
Liu, Jianwei ;
Xu, Tongge ;
Ren, Bohan ;
Mao, Jian ;
Zhang, Wei .
INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2020, 34 (01) :56-69
[24]  
Cisco Annual Internet Report, 2023, CISC VIS NETW IND GL
[25]  
community.fs, WHAT IS SOFTWARE DEF
[26]   Towards DDoS detection mechanisms in Software-Defined Networking [J].
Cui, Yunhe ;
Qian, Qing ;
Guo, Chun ;
Shen, Guowei ;
Tian, Youliang ;
Xing, Huanlai ;
Yan, Lianshan .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 190
[27]  
Deepa V., 2022, 2022 International Conference on Data Science, Agents & Artificial Intelligence (ICDSAAI), P1, DOI 10.1109/ICDSAAI55433.2022.10028880
[28]  
Dey S.K., 2020, P INT JOINT C COMP I, P483, DOI DOI 10.1007/978-981-13-7564-441
[29]  
Dhamecha K., 2013, INT J COMPUTER APPL, V73, P30, DOI [10.5120/12843-0195, DOI 10.5120/12843-0195]
[30]   A Survey on Distributed Denial of Service (DDoS) Attacks in SDN and Cloud Computing Environments [J].
Dong, Shi ;
Abbas, Khushnood ;
Jain, Raj .
IEEE ACCESS, 2019, 7 :80813-80828