An integrated SDN framework for early detection of DDoS attacks in cloud computing

被引:6
作者
Songa, Asha Varma [1 ]
Karri, Ganesh Reddy [1 ]
机构
[1] VIT AP Univ, Sch Comp Sci & Engn, Amaravati, Andhra Pradesh, India
来源
JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS | 2024年 / 13卷 / 01期
关键词
Cloud computing; SDN; DDOS; Event correlation; DBSCAN clustering; INTRUSION DETECTION; FEATURE-SELECTION; NEURAL-NETWORK; FLOW;
D O I
10.1186/s13677-024-00625-9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing is a rapidly advancing technology with numerous benefits, such as increased availability, scalability, and flexibility. Relocating computing infrastructure to a network simplifies hardware and software resource monitoring in the cloud. Software-Defined Networking (SDN)-based cloud networking improves cloud infrastructure efficiency by dynamically allocating and utilizing network resources. While SDN cloud networks offer numerous advantages, they are vulnerable to Distributed Denial-of-Service (DDoS) attacks. DDoS attacks try to stop genuine users from using services and drain network resources to reduce performance or shut down services. However, early-stage detection of DDoS attack patterns in cloud environments remains challenging. Current methods detect DDoS at the SDN controller level, which is often time-consuming. We recommend focusing on SDN switches for early detection. Due to the large volume of data from diverse sources, we recommend traffic clustering and traffic anomalies prediction which is of DDoS attacks at each switch. Furthermore, to consolidate the data from multiple clusters, event correlation is performed to understand network behavior and detect coordinated attack activities. Many existing techniques stay behind for early detection and integration of multiple techniques to detect DDoS attack patterns. In this paper, we introduce a more efficient and effectively integrated SDN framework that addresses a gap in previous DDoS solutions. Our framework enables early and accurate detection of DDoS traffic patterns within SDN-based cloud environments. In this framework, we use Recursive Feature Elimination (RFE), Density Based Spatial Clustering (DBSCAN), time series techniques like Auto Regressive Integrated Moving Average (ARIMA), Lyapunov exponent, exponential smoothing filter, dynamic threshold, and lastly, Rule-based classifier. We have evaluated the proposed RDAER model on the CICDDoS 2019 dataset, that achieved an accuracy level of 99.92% and a fast detection time of 20 s, outperforming existing methods.
引用
收藏
页数:22
相关论文
共 62 条
[1]   Distributed Denial of Service Attacks against Cloud Computing Environment: Survey, Issues, Challenges and Coherent Taxonomy [J].
Alashhab, Ziyad R. ;
Anbar, Mohammed ;
Singh, Manmeet Mahinderjit ;
Hasbullah, Iznan H. ;
Jain, Prateek ;
Al-Amiedy, Taief Alaa .
APPLIED SCIENCES-BASEL, 2022, 12 (23)
[2]   Complex methods detect anomalies in real time based on time series analysis [J].
Alghawli, Abed Saif .
ALEXANDRIA ENGINEERING JOURNAL, 2022, 61 (01) :549-561
[3]   Resilient Back Propagation Neural Network Security Model For Containerized Cloud Computing [J].
Almiani, Muder ;
Abughazleh, Alia ;
Jararweh, Yaser ;
Razaque, Abdul .
SIMULATION MODELLING PRACTICE AND THEORY, 2022, 118
[4]  
Alubaidan H., 2023, Int. J. Cybern. Inform, V12, P93, DOI [10.5121/ijci.2023.120408, DOI 10.5121/IJCI.2023.120408]
[5]  
Ates⠁ C., 2019, INT C INTELLIGENT FU, P338
[6]  
Aytac T., 2020, Detection of ddos attacks using machine learning methods, DOI [10.5152/electrica.2020.20049, DOI 10.5152/ELECTRICA.2020.20049]
[7]   A generalized machine learning model for DDoS attacks detection using hybrid feature selection and hyperparameter tuning [J].
Batchu, Raj Kumar ;
Seetha, Hari .
COMPUTER NETWORKS, 2021, 200
[8]   Hyperband Tuned Deep Neural Network With Well Posed Stacked Sparse AutoEncoder for Detection of DDoS Attacks in Cloud [J].
Bhardwaj, Aanshi ;
Mangat, Veenu ;
Vig, Renu .
IEEE ACCESS, 2020, 8 :181916-181929
[9]   Cloud Security Threats and Solutions: A Survey [J].
Butt, Umer Ahmed ;
Amin, Rashid ;
Mehmood, Muhammad ;
Aldabbas, Hamza ;
Alharbi, Mafawez T. ;
Albaqami, Nasser .
WIRELESS PERSONAL COMMUNICATIONS, 2023, 128 (01) :387-413
[10]  
Daffu P, 2016, 2016 5 INT C WIR NET, P1