A Comparative Study on the Performance Evaluation of DDoS Attack Detection Methods

被引:0
作者
Fouladi, Ramin Fadaei [1 ]
Ermis, Orhan [2 ]
Anarim, Emin [1 ]
机构
[1] Bogazici Univ, Elect & Elect Engn, Istanbul, Turkey
[2] Luxembourg Inst Sci & Technol LIST, IT Innovat Serv, Esch Sur Alzette, Luxembourg
来源
2022 30TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE, SIU | 2022年
关键词
DDoS; SDN; CWT; ARIMA; CNN;
D O I
10.1109/SIU55565.2022.9864872
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Software-Defined Networking (SDN) has emerged as an alternative for conventional network management architectures. Although SDN addresses the issues of conventional network relating to adaptability, flexibility and scalablity, due to its centralized controller, it is much more vulnerable to attacks on network availability like Distributed Denial of Service (DDoS) attack. Most of the proposed DDoS detection approaches for SDN are usually integrated into the controllers that have limited computing power and these detection approaches bring extra computational cost overhead for the controllers; therefore, while choosing the suitable approach the overall computational overhead should be taken into account together with the higher detection performance. In this paper, we compare two DDoS detection schemes with respect to detection performance and computational complexity cost. While one scheme is based on thresholding approach another one is based on Machine Learning (ML) approach. The result shows that the ML-based scheme outperforms the other in both detection performance and computational complexity cost.
引用
收藏
页数:4
相关论文
共 13 条
  • [1] A hybrid entropy-based DoS attacks detection system for software defined networks (SDN): A proposed trust mechanism
    AbdelAzim, Nada M.
    Fahmy, Sherif F.
    Sobh, Mohammed Ali
    Eldin, Ayman M. Bahaa
    [J]. EGYPTIAN INFORMATICS JOURNAL, 2021, 22 (01) : 85 - 90
  • [2] Seven Years and One Day: Sketching the Evolution of Internet Traffic
    Borgnat, Pierre
    Dewaele, Guillaume
    Fukuda, Kensuke
    Abry, Patrice
    Cho, Kenjiro
    [J]. IEEE INFOCOM 2009 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-5, 2009, : 711 - +
  • [3] A Novel Approach for distributed denial of service defense using continuous wavelet transform and convolutional neural network for software-Defined network
    Fouladi, Ramin Fadaei
    Ermis, Orhan
    Anarim, Emin
    [J]. COMPUTERS & SECURITY, 2022, 112
  • [4] Anomaly-Based DDoS Attack Detection by Using Sparse Coding and Frequency Domain
    Fouladi, Ramin Fadaei
    Ermis, Orhan
    Anarim, Emin
    [J]. 2019 IEEE 30TH ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS (PIMRC), 2019, : 1108 - 1113
  • [5] A DDoS attack detection and defense scheme using time-series analysis for SDN
    Fouladi, Ramin Fadaei
    Ermis, Orhan
    Anarim, Emin
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 54 (54)
  • [6] Fouladi RF, 2013, SIG PROCESS COMMUN
  • [7] Fouladi RF, 2016, 2016 39TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING (TSP), P104, DOI 10.1109/TSP.2016.7760838
  • [8] Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach
    Galeano-Brajones, Jesus
    Carmona-Murillo, Javier
    Valenzuela-Valdes, Juan F.
    Luna-Valero, Francisco
    [J]. SENSORS, 2020, 20 (03)
  • [9] Combining Open Flow and sFlow for an effective and scalable anomaly detection and mitigation mechanism on SDN environments
    Giotis, K.
    Argyropoulos, C.
    Androulidakis, G.
    Kalogeras, D.
    Maglaris, V.
    [J]. COMPUTER NETWORKS, 2014, 62 : 122 - 136
  • [10] A Deep CNN Ensemble Framework for Efficient DDoS Attack Detection in Software Defined Networks
    Haider, Shahzeb
    Akhunzada, Adnan
    Mustafa, Iqra
    Patel, Tanil Bharat
    Fernandez, Amanda
    Choo, Kim-Kwang Raymond
    Iqbal, Javed
    [J]. IEEE ACCESS, 2020, 8 : 53972 - 53983