On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN

被引:1
|
作者
Wu, Hao [1 ]
Hou, Aiqin [1 ]
Nie, Weike [1 ]
Wu, Chase [2 ]
机构
[1] Northwest Univ, Sch Informat Sci & Technol, Xian 710127, Shaanxi, Peoples R China
[2] New Jersey Inst Technol, Dept Data Sci, Newark, NJ 07102 USA
关键词
Software-Defined Networking; high-rate DDoS attack; low-rate DDoS attack; Slow-TCAM attack; attack defense;
D O I
10.1109/ICNC57223.2023.10074226
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As a new network paradigm, software-defined networking (SDN) technology has been increasingly adopted. Unfortunately, SDN-enabled networks are more prone to threats from DDoS attacks than traditional networks due to the nature of centralized management. We propose an integrated defense framework to detect and mitigate various types of DDoS attacks in SDN-enabled networks. The proposed framework deploys two technical modules in the control plane of SDN for defending against high-rate and low-rate DDoS attacks, respectively. The former module consists of three components, which watch out for suspicious traffic, detect attacks using ensemble learning, and intercept malicious packets, respectively. The latter module is designed specifically to defend against the Slow Ternary Content Addressable Memory (TCAM) exhaustion attack (Slow-TCAM) using a new Alleviative Threat for TCAM (ATFT) algorithm. The proposed framework is implemented and tested in simulated networks using Mininet and further evaluated on the CICDDoS2019 dataset. Experimental results illustrate the superior performance of the proposed framework in defending against different types of DDoS attacks in comparison with other state-of-the-art algorithms.
引用
收藏
页码:311 / 317
页数:7
相关论文
共 50 条
  • [41] A Cooperative Defense Framework Against Application-Level DDoS Attacks on Mobile Edge Computing Services
    Li, Hongjia
    Yang, Chang
    Wang, Liming
    Ansari, Nirwan
    Tang, Ding
    Huang, Xueqing
    Xu, Zhen
    Hu, Dan
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2023, 22 (01) : 1 - 18
  • [42] A adaptive filtration based defense framework against DDoS
    Zhang, Jian
    Zhou, Xiaxia
    Zhang, Wei
    Liang, Qidi
    Xiang, Fengtao
    2017 15TH IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS AND 2017 16TH IEEE INTERNATIONAL CONFERENCE ON UBIQUITOUS COMPUTING AND COMMUNICATIONS (ISPA/IUCC 2017), 2017, : 729 - 736
  • [43] Physical Assessment of an SDN-Based Security Framework for DDoS Attack Mitigation: Introducing the SDN-SlowRate-DDoS Dataset
    Yungaicela-Naula, Noe M.
    Vargas-Rosales, Cesar
    Perez-Diaz, Jesus Arturo
    Jacob, Eduardo
    Martinez-Cagnazzo, Carlos
    IEEE ACCESS, 2023, 11 : 46820 - 46831
  • [44] Improving Resiliency Against DDoS Attacks by SDN and Multipath Orchestration of VNF Services
    Alparslan, Onur
    Gunes, Onur
    Hanay, Y. Sinan
    Arakawa, Shin'ichi
    Murata, Masayuki
    2017 23RD IEEE INTERNATIONAL SYMPOSIUM ON LOCAL AND METROPOLITAN AREA NETWORKS (LANMAN), 2017,
  • [45] An SDN-Enabled Proactive Defense Framework for DDoS Mitigation in IoT Networks
    Zhou, Yuyang
    Cheng, Guang
    Yu, Shui
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 5366 - 5380
  • [46] SDN Control Plane Security in Cloud Computing Against DDoS Attack
    Khimabhai, Yadav Ashok
    Rohokale, Vandana
    INTERNATIONAL CONFERENCE ON ADVANCES IN INFORMATION COMMUNICATION TECHNOLOGY & COMPUTING, 2016, 2016,
  • [47] Cooperative security management enhancing survivability against DDoS attacks
    Kim, SK
    Min, YJ
    Jung, JC
    Yoo, SH
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2005, PT 1, 2005, 3480 : 252 - 260
  • [48] GridSec: Trusted grid computing with security binding and self-defense against network worms and DDoS attacks
    Hwang, K
    Kwok, YK
    Song, SS
    Chen, MCY
    Chen, Y
    Zhou, R
    Lou, XS
    COMPUTATIONAL SCIENCE - ICCS 2005, PT 3, 2005, 3516 : 187 - 195
  • [49] Adaptive defense against various network attacks
    Zou, Cliff C.
    Duffield, Nick
    Towsley, Don
    Gong, Weibo
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2006, 24 (10) : 1877 - 1888
  • [50] An Integrated Framework for Proactive Mitigation, Characterization and Traceback of DDoS Attacks
    Gandhi, Bhavana
    Joshi, R. C.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2007, 7 (03): : 274 - 282