A Method for DDoS Attacks Prevention Using SDN and NFV

被引:0
作者
Shayegan, Mohammad Javad [1 ]
Damghanian, Amirreza [1 ]
机构
[1] Univ Sci & Culture, Dept Comp Engn, Tehran 1461968151, Iran
关键词
Denial-of-service attack; Security; Network function virtualization; Computer crime; Bandwidth; Software; Servers; Network functions virtualization (NFV); virtualization of network functions (VNF); network security functions (NSF); virtualization; denial of service attack; moving target defense (MTD); DDos attacks; MOVING TARGET DEFENSE;
D O I
10.1109/ACCESS.2024.3438538
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial-of-Service (DDoS) attacks are among the most common security attacks in enterprise networks. DDoS attacks are designed to disrupt networks by sending many false requests. With the introduction of Network Functions Virtualization (NFV), a new paradigm has been created for network management and design. The NFV architecture allows network functions to be defined dquite dynamically. A dynamic definition of network functions will provide the most effective support for organizational environments. This research aims to prevent DDoS attacks using NFV and Software-Defined Networking(SDN) platforms. Moving Target Defense (MTD) is used in this research to alter the routing and location of particular detection packets in the network. This MTD technique effectively hinders attackers from targeting real network topologies. A significant innovation introduced in this research is the selection of MTD types based on the processing resources of overlay networks. The results indicate that the proposed method will save these resources and reduce the time required to check network packets.
引用
收藏
页码:108176 / 108184
页数:9
相关论文
共 40 条
[1]   An Effective Lightweight Intrusion Detection System with Blockchain to Mitigate Attacks in SDN/NFV Enabled Cloud [J].
Abdulqadder, Ihsan H. ;
Zhou, Shijie ;
Aziz, Israa T. ;
Zou, Deqing ;
Deng, Xianjun ;
Akber, Syed Muhammad Abrar .
2021 6TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2021,
[2]   Deployment of Robust Security Scheme in SDN Based 5G Network over NFV Enabled Cloud Environment [J].
Abdulqadder, Ihsan H. ;
Zou, Deqing ;
Aziz, Israa T. ;
Yuan, Bin ;
Dai, Weiqi .
IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2021, 9 (02) :866-877
[3]  
Agarwal Ankit, 2022, 2022 1st International Conference on Informatics (ICI)., P36, DOI 10.1109/ICI53355.2022.9786899
[4]   An SDN-Assisted Defense Mechduanism for the Shrew DDoS Attack in a Cloud Computing Environment [J].
Agrawal, Neha ;
Tapaswi, Shashikala .
JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2021, 29 (02)
[5]  
Akamai Blog, 2021, Volumetric DDoS Attacks Rising Fast
[6]   Real-time Pipeline Reconfiguration of P4 Programmable Switches to Efficiently Detect and Mitigate DDoS Attacks [J].
Al Sadi, Amir ;
Savi, Marco ;
Berardi, Davide ;
Melis, Andrea ;
Prandini, Marco ;
Callegati, Franco .
2023 26TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS, ICIN, 2023,
[7]   Evaluating the Security and Economic Effects of Moving Target Defense Techniques on the Cloud [J].
Alavizadeh, Hooman ;
Aref, Samin ;
Kim, Dong Seong ;
Jang-Jaccard, Julian .
IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2022, 10 (04) :1772-1788
[8]   Modeling and Mitigating Security Threats in Network Functions Virtualization (NFV) [J].
Alhebaishi, Nawaf ;
Wang, Lingyu ;
Jajodia, Sushil .
DATA AND APPLICATIONS SECURITY AND PRIVACY XXXIV, DBSEC 2020, 2020, 12122 :3-23
[9]   A survey on DoS/DDoS mitigation techniques in SDNs: Classification, comparison, solutions, testing tools and datasets [J].
Alhijawi, Bushra ;
Almajali, Sufyan ;
Elgala, Hany ;
Salameh, Haythem Bany ;
Ayyash, Moussa .
COMPUTERS & ELECTRICAL ENGINEERING, 2022, 99
[10]   A moving target defense and network forensics framework for ISP networks using SDN and NFV [J].
Aydeger, Abdullah ;
Saputro, Nico ;
Akkaya, Kemal .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 94 :496-509