On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN

被引:1
|
作者
Wu, Hao [1 ]
Hou, Aiqin [1 ]
Nie, Weike [1 ]
Wu, Chase [2 ]
机构
[1] Northwest Univ, Sch Informat Sci & Technol, Xian 710127, Shaanxi, Peoples R China
[2] New Jersey Inst Technol, Dept Data Sci, Newark, NJ 07102 USA
关键词
Software-Defined Networking; high-rate DDoS attack; low-rate DDoS attack; Slow-TCAM attack; attack defense;
D O I
10.1109/ICNC57223.2023.10074226
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As a new network paradigm, software-defined networking (SDN) technology has been increasingly adopted. Unfortunately, SDN-enabled networks are more prone to threats from DDoS attacks than traditional networks due to the nature of centralized management. We propose an integrated defense framework to detect and mitigate various types of DDoS attacks in SDN-enabled networks. The proposed framework deploys two technical modules in the control plane of SDN for defending against high-rate and low-rate DDoS attacks, respectively. The former module consists of three components, which watch out for suspicious traffic, detect attacks using ensemble learning, and intercept malicious packets, respectively. The latter module is designed specifically to defend against the Slow Ternary Content Addressable Memory (TCAM) exhaustion attack (Slow-TCAM) using a new Alleviative Threat for TCAM (ATFT) algorithm. The proposed framework is implemented and tested in simulated networks using Mininet and further evaluated on the CICDDoS2019 dataset. Experimental results illustrate the superior performance of the proposed framework in defending against different types of DDoS attacks in comparison with other state-of-the-art algorithms.
引用
收藏
页码:311 / 317
页数:7
相关论文
共 50 条
  • [21] A Cost-Effective Shuffling-Based Defense against HTTP DDoS Attacks with SDN/NFV
    Lin, Yi-Hui
    Kuo, Jian-Jhih
    Yang, De-Nian
    Chen, Wen-Tsuen
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [22] A New Framework for DDoS Attack Detection and Defense in SDN Environment
    Tan, Liang
    Pan, Yue
    Wu, Jing
    Zhou, Jianguo
    Jiang, Hao
    Deng, Yuchuan
    IEEE ACCESS, 2020, 8 : 161908 - 161919
  • [23] Lightweight Algorithm for Protecting SDN controller against DDoS attacks
    Gkountis, Christos
    Taha, Miran
    Lloret, Jaime
    Kambourakis, Georgios
    2017 10TH IFIP WIRELESS AND MOBILE NETWORKING CONFERENCE (WMNC 2017), 2017,
  • [24] A protocol for cluster confirmations of SDN controllers against DDoS attacks
    Iranmanesh, Amir
    Naji, Hamid Reza
    COMPUTERS & ELECTRICAL ENGINEERING, 2021, 93
  • [25] Detection and Defense Mechanisms Against DDoS Attacks: A Review
    Pimpalkar, Archana S.
    Patil, A. R. Bhagat
    2015 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2015,
  • [26] Mitigating while Accessing: A Lightweight Defense Framework Against Link Flooding Attacks in SDN
    Sun, Hancun
    Chen, Xu
    Luo, Yantian
    Ge, Ning
    CHINA COMMUNICATIONS, 2024, 21 (11) : 15 - 27
  • [27] Mitigating while Accessing: A Lightweight Defense Framework Against Link Flooding Attacks in SDN
    Sun Hancun
    Chen Xu
    Luo Yantian
    Ge Ning
    China Communications, 2024, 21 (11) : 15 - 27
  • [28] SDN-Assisted DDoS Defense Framework for the Internet of Multimedia Things
    Sahoo, Kshira Sagar
    Puthal, Deepak
    ACM TRANSACTIONS ON MULTIMEDIA COMPUTING COMMUNICATIONS AND APPLICATIONS, 2021, 16 (03)
  • [29] An SDN-based Approach For Defending Against Reflective DDoS Attacks
    Lukaseder, Thomas
    StOlzle, Kevin
    Kleber, Stephan
    Erb, Benjamin
    Kargl, Frank
    PROCEEDINGS OF THE 2018 IEEE 43RD CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2018, : 299 - 302
  • [30] A distributed defense framework for flooding-based DDoS attacks
    You, Yonghua
    Zulkernine, Mohammad
    Haque, Anwar
    ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY, 2008, : 245 - +