IQR-based approach for DDoS detection and mitigation in SDN

被引:6
|
作者
Swami, Rochak [1 ]
Dave, Mayank [1 ]
Ranga, Virender [2 ]
机构
[1] Natl Inst Technol, Dept Comp Engn, Kurukshetra, India
[2] Delhi Technol Univ, Dept Informat Technol, Delhi, India
来源
DEFENCE TECHNOLOGY | 2023年 / 25卷
关键词
SDN; DdoS; IQR; Controller; CPU utilization; Packet_in; SOFTWARE-DEFINED NETWORKING; DEFENSE-MECHANISMS; ATTACKS; DOS;
D O I
10.1016/j.dt.2022.10.006
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Software-defined networking (SDN) is a trending networking paradigm that focuses on decoupling of the control logic from the data plane. This decoupling brings programmability and flexibility for the network management by introducing centralized infrastructure. The complete control logic resides in the controller, and thus it becomes the intellectual and most important entity of the SDN infrastructure. With these advantages, SDN faces several security issues in various SDN layers that may prevent the growth and global adoption of this groundbreaking technology. Control plane exhaustion and switch buffer overflow are examples of such security issues. Distributed denial-of-service (DDoS) attacks are one of the most severe attacks that aim to exhaust the controller's CPU to discontinue the whole functioning of the SDN network. Hence, it is necessary to design a quick as well as accurate detection scheme to detect the attack traffic at an early stage. In this paper, we present a defense solution to detect and mitigate spoofed flooding DDoS attacks. The proposed defense solution is implemented in the SDN controller. The detection method is based on the idea of an statistical measure d Interquartile Range (IQR). For the mitigation purpose, the existing SDN-in-built capabilities are utilized. In this work, the experiments are performed considering the spoofed SYN flooding attack. The proposed solution is evaluated using different performance parameters, i.e., detection time, detection accuracy, packet_in messages, and CPU utilization. The experimental results reveal that the proposed defense solution detects and mitigates the attack effectively in different attack scenarios.& COPY; 2022 China Ordnance Society. Publishing services by Elsevier B.V. on behalf of KeAi Communications Co. Ltd. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/ licenses/by-nc-nd/4.0/).
引用
收藏
页码:76 / 87
页数:12
相关论文
共 50 条
  • [31] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    M. Revathi
    V. V. Ramalingam
    B. Amutha
    Wireless Personal Communications, 2022, 127 (3) : 2417 - 2441
  • [32] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    Revathi, M.
    Ramalingam, V. V.
    Amutha, B.
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (03) : 2417 - 2441
  • [33] Detection and mitigation of attacks in SDN-based IoT network using SVM
    Mishra, Shailendra
    INTERNATIONAL JOURNAL OF COMPUTER APPLICATIONS IN TECHNOLOGY, 2021, 65 (03) : 270 - 281
  • [34] BSD-Guard: A Collaborative Blockchain-Based Approach for Detection and Mitigation of SDN-Targeted DDoS Attacks
    Jiang, Shanqing
    Yang, Lin
    Gao, Xianming
    Zhou, Yuyang
    Feng, Tao
    Song, Yanbo
    Liu, Kexian
    Cheng, Guang
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [35] DDoS Mitigation: A Measurement-Based Approach
    Jonker, Mattijs
    Sperotto, Anna
    Pras, Aiko
    NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE, 2020,
  • [36] Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions
    Singh, Jagdeep
    Behal, Sunny
    COMPUTER SCIENCE REVIEW, 2020, 37
  • [37] An Intelligent ML-Based IDS Framework for DDoS Detection in the SDN Environment
    Chetouane, Ameni
    Karoui, Kamel
    Nemri, Ghayth
    ADVANCES IN MOBILE COMPUTING AND MULTIMEDIA INTELLIGENCE, MOMM 2022, 2022, 13634 : 18 - 31
  • [38] Co-IoT: A Collaborative DDoS mitigation scheme in IoT environment based on blockchain using SDN
    El Houda, Zakaria Abou
    Hafid, Abdelhakim
    Khoukhi, Lyes
    2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [39] An optimized weighted voting based ensemble model for DDoS attack detection and mitigation in SDN environment
    Maheshwari, Aastha
    Mehraj, Burhan
    Khan, Mohd Shaad
    Idrisi, Mohd Shaheem
    MICROPROCESSORS AND MICROSYSTEMS, 2022, 89
  • [40] DDoS SourceTracer: An Intelligent Application for DDoS Attack Mitigation in SDN
    Aslam, Naziya
    Srivastava, Shashank
    Gore, M. M.
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 117