Detection and Mitigation of ICMP-based DDoS in Software Defined Networks

被引:0
|
作者
Shehabat, Marah M. [1 ]
Shurman, Mohammad M. [1 ]
机构
[1] Jordan Univ Sci & Technol, Network Engn & Secur Dept, Irbid, Jordan
来源
2024 15TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS, ICICS 2024 | 2024年
关键词
QoS; DoS; ICMP; SDN; Machine learning (ML);
D O I
10.1109/ICICS63486.2024.10638300
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
ICMP-based distributed denial of service (DDoS) attacks significantly impact the reliability and security of software-defined networks (SDN). Our research focuses on efficiently distinguishing between regular and malicious ICMP network traffic in SDN through a two-level detection system. The first layer employs a dynamic threshold-based model, while the second layer utilizes Hoeffding trees. Furthermore, we propose a mitigation paradigm that integrates dynamic blacklisting with blackhole routing, effectively addressing current risks and enhancing network resilience against future attacks. Extensive simulations demonstrate performance improvements, with accuracy increasing from 89% to 96%-an 7% rise over the simulation period. Additionally, false negatives and false positives were reduced by 49% and 36%, respectively. Our approach improves the detection and response to ICMP-based DDoS attacks and outperforms traditional methods, marking a significant advancement in SDN security and the management of complex cyber threats.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Mitigation and Detection of DDoS Attacks in Software Defined Networks
    Murtuza, Shariq
    Asawa, Krishna
    2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 389 - 391
  • [2] Collaborative detection and mitigation of DDoS in software-defined networks
    Omer Elsier Tayfour
    Muhammad Nadzir Marsono
    The Journal of Supercomputing, 2021, 77 : 13166 - 13190
  • [3] Collaborative detection and mitigation of DDoS in software-defined networks
    Tayfour, Omer Elsier
    Marsono, Muhammad Nadzir
    JOURNAL OF SUPERCOMPUTING, 2021, 77 (11): : 13166 - 13190
  • [4] Entropy based DDoS Detection in Software Defined Networks
    Fioravanti, Giovanni
    Spina, Mattia Giovanni
    De Rango, Floriano
    2023 IEEE 20TH CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2023,
  • [5] Future of DDoS Attacks Mitigation in Software Defined Networks
    Vizvary, Martin
    Vykopal, Jan
    MONITORING AND SECURING VIRTUALIZED NETWORKS AND SERVICES, 2014, 8508 : 123 - 127
  • [6] DDoS Flooding Attack Mitigation in Software Defined Networks
    Mahrach, Safaa
    Haqiq, Abdelkrim
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (01) : 693 - 700
  • [7] A comprehensive survey on DDoS detection, mitigation, and defense strategies in software-defined networks
    Jain, Ankit Kumar
    Shukla, Hariom
    Goel, Diksha
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (09): : 13129 - 13164
  • [8] Mitigation of DDoS attacks in Software Defined Networks at application level
    Sanjeetha, R.
    Benoor, Pallavi
    Kanavalli, Anita
    2019 PHD COLLOQUIUM ON ETHICALLY DRIVEN INNOVATION AND TECHNOLOGY FOR SOCIETY (PHD EDITS), 2019,
  • [9] Edge DDoS Attack Detection Method Based on Software Defined Networks
    Ren, Gangsheng
    Zhang, Yang
    Zhang, Shukui
    Long, Hao
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT I, 2022, 13155 : 597 - 611
  • [10] Closed-Loop DDoS Mitigation System in Software Defined Networks
    Hyder, Henan Kottayil
    Lung, Chung-Horng
    2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2018, : 288 - 293