On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN

被引:1
|
作者
Wu, Hao [1 ]
Hou, Aiqin [1 ]
Nie, Weike [1 ]
Wu, Chase [2 ]
机构
[1] Northwest Univ, Sch Informat Sci & Technol, Xian 710127, Shaanxi, Peoples R China
[2] New Jersey Inst Technol, Dept Data Sci, Newark, NJ 07102 USA
关键词
Software-Defined Networking; high-rate DDoS attack; low-rate DDoS attack; Slow-TCAM attack; attack defense;
D O I
10.1109/ICNC57223.2023.10074226
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As a new network paradigm, software-defined networking (SDN) technology has been increasingly adopted. Unfortunately, SDN-enabled networks are more prone to threats from DDoS attacks than traditional networks due to the nature of centralized management. We propose an integrated defense framework to detect and mitigate various types of DDoS attacks in SDN-enabled networks. The proposed framework deploys two technical modules in the control plane of SDN for defending against high-rate and low-rate DDoS attacks, respectively. The former module consists of three components, which watch out for suspicious traffic, detect attacks using ensemble learning, and intercept malicious packets, respectively. The latter module is designed specifically to defend against the Slow Ternary Content Addressable Memory (TCAM) exhaustion attack (Slow-TCAM) using a new Alleviative Threat for TCAM (ATFT) algorithm. The proposed framework is implemented and tested in simulated networks using Mininet and further evaluated on the CICDDoS2019 dataset. Experimental results illustrate the superior performance of the proposed framework in defending against different types of DDoS attacks in comparison with other state-of-the-art algorithms.
引用
收藏
页码:311 / 317
页数:7
相关论文
共 50 条
  • [31] Multi-Defense Mechanism against DDoS in SDN based CDNi
    Nishat-I-Mowla
    Doh, Inshil
    Chae, Kijoon
    2014 Eighth International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2014, : 447 - 451
  • [32] A Comprehensive Survey of Distributed Defense Techniques against DDoS Attacks
    Sachdeva, Monika
    Singh, Gurvinder
    Kumar, Krishan
    Singh, Kuldip
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2009, 9 (12): : 7 - 15
  • [33] MSOM: Efficient Mechanism for Defense against DDoS Attacks in VANET
    Al-Mehdhara, Mohammed
    Ruan, Na
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [34] Global Orchestration of Cooperative Defense against DDoS Attacks for MEC
    Tan, Xinrui
    Li, Hongjia
    Wang, Liming
    Xu, Zhen
    2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,
  • [35] Distributed and Predictive-Preventive Defense Against DDoS Attacks
    Jog, Manjiri
    Natu, Maitreya
    Shelke, Sushama
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING, 2015,
  • [36] METHODOLOGIES FOR EVALUATING GAME THEORETIC DEFENSE AGAINST DDOS ATTACKS
    Khirwadkar, Tanmay
    Nguyen, Kien C.
    Nicol, David M.
    Basar, Tamer
    PROCEEDINGS OF THE 2010 WINTER SIMULATION CONFERENCE, 2010, : 697 - 707
  • [37] gore:: Routing-assisted defense against DDoS attacks
    Chou, ST
    Stavrou, A
    Ioannidis, J
    Keromytis, AD
    INFORMATION SECURITY, PROCEEDINGS, 2005, 3650 : 179 - 193
  • [38] Framework for statistical filtering against DDoS attacks in MANETs
    Tan, HX
    Seah, WKG
    ICESS 2005: SECOND INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2005, : 456 - 463
  • [39] An Effective DDoS Defense Scheme for SDN
    Huang, Xueli
    Du, Xiaojiang
    Song, Bin
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [40] DDoS Defense using MTD and SDN
    Steinberger, Jessica
    Kuhnert, Benjamin
    Dietz, Christian
    Ball, Lisa
    Sperotto, Anna
    Baier, Harald
    Pras, Aiko
    Dreo, Gabi
    NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,