Detection and Mitigation of ICMP-based DDoS in Software Defined Networks

被引:0
|
作者
Shehabat, Marah M. [1 ]
Shurman, Mohammad M. [1 ]
机构
[1] Jordan Univ Sci & Technol, Network Engn & Secur Dept, Irbid, Jordan
来源
2024 15TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS, ICICS 2024 | 2024年
关键词
QoS; DoS; ICMP; SDN; Machine learning (ML);
D O I
10.1109/ICICS63486.2024.10638300
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
ICMP-based distributed denial of service (DDoS) attacks significantly impact the reliability and security of software-defined networks (SDN). Our research focuses on efficiently distinguishing between regular and malicious ICMP network traffic in SDN through a two-level detection system. The first layer employs a dynamic threshold-based model, while the second layer utilizes Hoeffding trees. Furthermore, we propose a mitigation paradigm that integrates dynamic blacklisting with blackhole routing, effectively addressing current risks and enhancing network resilience against future attacks. Extensive simulations demonstrate performance improvements, with accuracy increasing from 89% to 96%-an 7% rise over the simulation period. Additionally, false negatives and false positives were reduced by 49% and 36%, respectively. Our approach improves the detection and response to ICMP-based DDoS attacks and outperforms traditional methods, marking a significant advancement in SDN security and the management of complex cyber threats.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)
    Linhares, Tiago
    Patel, Ahmed
    Barros, Ana Luiza
    Fernandez, Marcial
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (03)
  • [42] Effectiveness of Entropy-Based DDoS Prevention for Software Defined Networks
    Whittle, Cameron S.
    Liu, Hong
    2021 IEEE VIRTUAL IEEE INTERNATIONAL SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY, 2021,
  • [43] EVALUATION OF SUPERVISED CLASSIFICATION APPROACH FOR DDoS THREAT DETECTION IN SOFTWARE DEFINED NETWORKS
    Rakesh, V. S.
    Vasanthakumar, G. U.
    INTERNATIONAL JOURNAL ON INFORMATION TECHNOLOGIES AND SECURITY, 2024, 16 (04): : 95 - 104
  • [44] Improved Network Monitoring Using Software-Defined Networking for DDoS Detection and Mitigation Evaluation
    J. Ramprasath
    V. Seethalakshmi
    Wireless Personal Communications, 2021, 116 : 2743 - 2757
  • [45] Improved Network Monitoring Using Software-Defined Networking for DDoS Detection and Mitigation Evaluation
    Ramprasath, J.
    Seethalakshmi, V.
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 116 (03) : 2743 - 2757
  • [46] A DDoS Attack Detection Method Based on SVM in Software Defined Network
    Ye, Jin
    Cheng, Xiangyang
    Zhu, Jian
    Feng, Luting
    Song, Ling
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [47] Joint DDoS detection system based on software-defined networking
    Song Y.
    Yang H.
    Wu W.
    Hu A.
    Gao S.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (01): : 28 - 35
  • [48] A Survey of Low Rate DDoS Detection Techniques Based on Machine Learning in Software-Defined Networks
    Alashhab, Abdussalam Ahmed
    Zahid, Mohd Soperi Mohd
    Azim, Mohamed A.
    Daha, Muhammad Yunis
    Isyaku, Babangida
    Ali, Shimhaz
    SYMMETRY-BASEL, 2022, 14 (08):
  • [49] Detection and mitigation of link flooding-based DDoS attacks on a software defined network using network function virtualisation
    Murtuza, Shariq
    Asawa, Krishna
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2024, 30 (02) : 202 - 226
  • [50] Detection and Mitigation of ARP Storm Attacks using Software Defined Networks
    Numan, Munther
    Hashim, Fazirulhisyam
    Latiff, Nurul Adilah Abdul
    2017 IEEE 13TH MALAYSIA INTERNATIONAL CONFERENCE ON COMMUNICATIONS (MICC), 2017, : 181 - 186