Detection and Mitigation of ICMP-based DDoS in Software Defined Networks

被引:0
|
作者
Shehabat, Marah M. [1 ]
Shurman, Mohammad M. [1 ]
机构
[1] Jordan Univ Sci & Technol, Network Engn & Secur Dept, Irbid, Jordan
来源
2024 15TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS, ICICS 2024 | 2024年
关键词
QoS; DoS; ICMP; SDN; Machine learning (ML);
D O I
10.1109/ICICS63486.2024.10638300
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
ICMP-based distributed denial of service (DDoS) attacks significantly impact the reliability and security of software-defined networks (SDN). Our research focuses on efficiently distinguishing between regular and malicious ICMP network traffic in SDN through a two-level detection system. The first layer employs a dynamic threshold-based model, while the second layer utilizes Hoeffding trees. Furthermore, we propose a mitigation paradigm that integrates dynamic blacklisting with blackhole routing, effectively addressing current risks and enhancing network resilience against future attacks. Extensive simulations demonstrate performance improvements, with accuracy increasing from 89% to 96%-an 7% rise over the simulation period. Additionally, false negatives and false positives were reduced by 49% and 36%, respectively. Our approach improves the detection and response to ICMP-based DDoS attacks and outperforms traditional methods, marking a significant advancement in SDN security and the management of complex cyber threats.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Detection and Mitigation of DDoS Attacks Using Conditional Entropy in Software-defined Networking
    Xuanyuan, Ming
    Ramsurrun, Visham
    Seeam, Amar
    2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 66 - 71
  • [32] Improved Automated Graph and FCM Based DDoS Attack Detection Mechanism in Software Defined Networks
    Li, Xin
    Fan, Zhijie
    Xiao, Ya
    Xu, Qian
    Zhu, Wenye
    JOURNAL OF INTERNET TECHNOLOGY, 2019, 20 (07): : 2117 - 2127
  • [33] A DDoS Detection Method Based on Feature Engineering and Machine Learning in Software-Defined Networks
    Liu, Zhenpeng
    Wang, Yihang
    Feng, Fan
    Liu, Yifan
    Li, Zelin
    Shan, Yawei
    SENSORS, 2023, 23 (13)
  • [34] Simulation of DDoS Attack on Software Defined Networks
    Bikbulatov, Timur R.
    Kurochkin, Ilya I.
    COMPUTATIONAL MECHANICS AND MODERN APPLIED SOFTWARE SYSTEMS (CMMASS'2019), 2019, 2181
  • [35] DDoS Attack in Software Defined Networks: A Survey
    XU Xiaoqiong
    YU Hongfang
    YANG Kun
    ZTECommunications, 2017, 15 (03) : 13 - 19
  • [36] Optimized deep neural network based DDoS attack detection and bait mitigation process in software defined network
    Perumal, Karthika
    Arockiasamy, Karmel
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (12):
  • [37] Analyzing effective mitigation of DDoS attack with software defined networking
    Dayal, Neelam
    Srivastava, Shashank
    COMPUTERS & SECURITY, 2023, 130
  • [38] Flooding DDoS Mitigation and Traffic Management with Software Defined Networking
    Kalliola, Aapo
    Lee, Kiryong
    Lee, Heejo
    Aura, Tuomas
    2015 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (CLOUDNET), 2015, : 248 - 254
  • [39] SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)
    Tiago Linhares
    Ahmed Patel
    Ana Luiza Barros
    Marcial Fernandez
    Journal of Network and Systems Management, 2023, 31
  • [40] Detecting DDoS based on attention mechanism for Software-Defined Networks
    Yoon, Namkyung
    Kim, Hwangnam
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 230