An integrated SDN framework for early detection of DDoS attacks in cloud computing

被引:2
|
作者
Songa, Asha Varma [1 ]
Karri, Ganesh Reddy [1 ]
机构
[1] VIT AP Univ, Sch Comp Sci & Engn, Amaravati, Andhra Pradesh, India
关键词
Cloud computing; SDN; DDOS; Event correlation; DBSCAN clustering; INTRUSION DETECTION; FEATURE-SELECTION; NEURAL-NETWORK; FLOW;
D O I
10.1186/s13677-024-00625-9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing is a rapidly advancing technology with numerous benefits, such as increased availability, scalability, and flexibility. Relocating computing infrastructure to a network simplifies hardware and software resource monitoring in the cloud. Software-Defined Networking (SDN)-based cloud networking improves cloud infrastructure efficiency by dynamically allocating and utilizing network resources. While SDN cloud networks offer numerous advantages, they are vulnerable to Distributed Denial-of-Service (DDoS) attacks. DDoS attacks try to stop genuine users from using services and drain network resources to reduce performance or shut down services. However, early-stage detection of DDoS attack patterns in cloud environments remains challenging. Current methods detect DDoS at the SDN controller level, which is often time-consuming. We recommend focusing on SDN switches for early detection. Due to the large volume of data from diverse sources, we recommend traffic clustering and traffic anomalies prediction which is of DDoS attacks at each switch. Furthermore, to consolidate the data from multiple clusters, event correlation is performed to understand network behavior and detect coordinated attack activities. Many existing techniques stay behind for early detection and integration of multiple techniques to detect DDoS attack patterns. In this paper, we introduce a more efficient and effectively integrated SDN framework that addresses a gap in previous DDoS solutions. Our framework enables early and accurate detection of DDoS traffic patterns within SDN-based cloud environments. In this framework, we use Recursive Feature Elimination (RFE), Density Based Spatial Clustering (DBSCAN), time series techniques like Auto Regressive Integrated Moving Average (ARIMA), Lyapunov exponent, exponential smoothing filter, dynamic threshold, and lastly, Rule-based classifier. We have evaluated the proposed RDAER model on the CICDDoS 2019 dataset, that achieved an accuracy level of 99.92% and a fast detection time of 20 s, outperforming existing methods.
引用
收藏
页数:22
相关论文
共 50 条
  • [31] Analysis of DDoS Attacks and an Introduction of a Hybrid Statistical Model to Detect DDoS Attacks on Cloud Computing Environment
    Girma, Anteneh
    Garuba, Moses
    Li, Jiang
    Liu, Chunmei
    2015 12TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY - NEW GENERATIONS, 2015, : 212 - 217
  • [32] DDoS Attacks Detection and Mitigation in SDN using Machine Learning
    Rahman, Obaid
    Quraishi, Mohammad Ali Gauhar
    Lung, Chung-Horng
    2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 184 - 189
  • [33] E-Had: A distributed and collaborative detection framework for early detection of DDoS attacks
    Patil, Nilesh Vishwasrao
    Krishna, C. Rama
    Kumar, Krishan
    Behal, Sunny
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (04) : 1373 - 1387
  • [34] SDN Control Plane Security in Cloud Computing Against DDoS Attack
    Khimabhai, Yadav Ashok
    Rohokale, Vandana
    INTERNATIONAL CONFERENCE ON ADVANCES IN INFORMATION COMMUNICATION TECHNOLOGY & COMPUTING, 2016, 2016,
  • [35] Proactive Approach for the Prevention of DDoS Attacks in Cloud Computing Environments
    Alshehry, Badr
    Allen, William
    APPLIED COMPUTING AND INFORMATION TECHNOLOGY, 2017, 695 : 119 - 133
  • [36] Simulated Raindrop Algorithm to Mitigate DDoS Attacks in Cloud Computing
    Bhagat, Sourabh
    Pasupuleti, Syam Kumar
    6TH INTERNATIONAL CONFERENCE ON COMPUTER & COMMUNICATION TECHNOLOGY (ICCCT-2015), 2015, : 412 - 418
  • [37] DDoS attacks in cloud computing: Issues, taxonomy, and future directions
    Somani, Gaurav
    Gaur, Manoj Singh
    Sanghi, Dheeraj
    Conti, Mauro
    Buyya, Rajkumar
    COMPUTER COMMUNICATIONS, 2017, 107 : 30 - 48
  • [38] Intrusion detection and prevention of DDoS attacks in cloud computing environment: a review on issues and current methods
    Devi B.S.K.
    Subbulakshmi T.
    International Journal of Cloud Computing, 2023, 12 (05) : 450 - 481
  • [39] Collaborative prediction and detection of DDoS attacks in edge computing: A deep learning-based approach with distributed SDN
    Zhou, Hongliang
    Zheng, Yifeng
    Jia, Xiaohua
    Shu, Jiangang
    COMPUTER NETWORKS, 2023, 225
  • [40] LRDADF: An AI enabled framework for detecting low-rate DDoS attacks in cloud computing environments
    Pasha M.J.
    Rao K.P.
    MallaReddy A.
    Bande V.
    Measurement: Sensors, 2023, 28