IQR-based approach for DDoS detection and mitigation in SDN

被引:6
|
作者
Swami, Rochak [1 ]
Dave, Mayank [1 ]
Ranga, Virender [2 ]
机构
[1] Natl Inst Technol, Dept Comp Engn, Kurukshetra, India
[2] Delhi Technol Univ, Dept Informat Technol, Delhi, India
来源
DEFENCE TECHNOLOGY | 2023年 / 25卷
关键词
SDN; DdoS; IQR; Controller; CPU utilization; Packet_in; SOFTWARE-DEFINED NETWORKING; DEFENSE-MECHANISMS; ATTACKS; DOS;
D O I
10.1016/j.dt.2022.10.006
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Software-defined networking (SDN) is a trending networking paradigm that focuses on decoupling of the control logic from the data plane. This decoupling brings programmability and flexibility for the network management by introducing centralized infrastructure. The complete control logic resides in the controller, and thus it becomes the intellectual and most important entity of the SDN infrastructure. With these advantages, SDN faces several security issues in various SDN layers that may prevent the growth and global adoption of this groundbreaking technology. Control plane exhaustion and switch buffer overflow are examples of such security issues. Distributed denial-of-service (DDoS) attacks are one of the most severe attacks that aim to exhaust the controller's CPU to discontinue the whole functioning of the SDN network. Hence, it is necessary to design a quick as well as accurate detection scheme to detect the attack traffic at an early stage. In this paper, we present a defense solution to detect and mitigate spoofed flooding DDoS attacks. The proposed defense solution is implemented in the SDN controller. The detection method is based on the idea of an statistical measure d Interquartile Range (IQR). For the mitigation purpose, the existing SDN-in-built capabilities are utilized. In this work, the experiments are performed considering the spoofed SYN flooding attack. The proposed solution is evaluated using different performance parameters, i.e., detection time, detection accuracy, packet_in messages, and CPU utilization. The experimental results reveal that the proposed defense solution detects and mitigates the attack effectively in different attack scenarios.& COPY; 2022 China Ordnance Society. Publishing services by Elsevier B.V. on behalf of KeAi Communications Co. Ltd. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/ licenses/by-nc-nd/4.0/).
引用
收藏
页码:76 / 87
页数:12
相关论文
共 50 条
  • [1] Detection and mitigation of DDoS in SDN
    Pande, Bhavika
    Bhagat, Gargi
    Priya, Shanu
    Agrawal, Himanshu
    2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 371 - 373
  • [2] DDoS Attack Detection and Mitigation Using SDN: Methods, Practices, and Solutions
    Bawany, Narmeen Zakaria
    Shamsi, Jawwad A.
    Salah, Khaled
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2017, 42 (02) : 425 - 441
  • [3] SDN Based Collaborative Scheme for Mitigation of DDoS Attacks
    Hameed, Sufian
    Khan, Hassan Ahmed
    FUTURE INTERNET, 2018, 10 (03)
  • [4] DoubleTrApp: A Weak Vertex Cover based DDoS Detection and Mitigation scheme using SDN approach
    Bardalai, Priyanka
    Medhi, Nabajyoti
    Chakraborty, Swarnendu Kumar
    13TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATION SYSTEMS (IEEE ANTS), 2019,
  • [5] Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach
    Galeano-Brajones, Jesus
    Carmona-Murillo, Javier
    Valenzuela-Valdes, Juan F.
    Luna-Valero, Francisco
    SENSORS, 2020, 20 (03)
  • [6] DNS Amplification Based DDoS Attacks in SDN Environment: Detection and Mitigation
    Gupta, Vishal
    Kochar, Amrit
    Saharan, Shail
    Kulshrestha, Rakhee
    2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 473 - 478
  • [7] Leveraging SDN for Collaborative DDoS Mitigation
    Hameed, Sufian
    Khan, Hassan Ahmed
    2017 INTERNATIONAL CONFERENCE ON NETWORKED SYSTEMS (NETSYS), 2017,
  • [8] Review of game theory approaches for DDoS mitigation by SDN
    Rathore, Shivani
    Bhandari, Abhinav
    PROCEEDINGS OF THE INDIAN NATIONAL SCIENCE ACADEMY, 2022, 88 (04): : 634 - 650
  • [9] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    INFORMATION, 2019, 10 (03)
  • [10] SDN/NFV-based DDoS Mitigation via Pushback
    Bulbul, Nurefsan Sertbas
    Fischer, Mathias
    ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,