A framework to detect DDoS attack in Ryu controller based software defined networks using feature extraction and classification

被引:16
作者
Chouhan, Ravindra Kumar [1 ]
Atulkar, Mithilesh [1 ]
Nagwani, Naresh Kumar [2 ]
机构
[1] NIT Raipur, Dept Comp Applicat, Raipur, Madhya Pradesh, India
[2] NIT Raipur, Dept Comp Sci & Engn, Raipur, Madhya Pradesh, India
关键词
SDN; DDoS attack; Machine learning; Feature extraction; Classification; Ryu; ENTROPY; MITIGATION; DEFENSE; SCHEME;
D O I
10.1007/s10489-022-03565-6
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Software Defined Network(SDN) is an emerging network architecture and is being used in many IT industries and academia. Its popularity in the present age has attracted many attacks in SDN. Distributed Denial of Service(DDoS) attack is a common issue in the domain of network security. In this work, DDoS attack detection is done using feature extraction and classification from the live traffic of SDN. An effective feature extraction mechanism will not only help in filtering the most suitable task-relevant data but also improve the performance of machine learning algorithms. To identify the best performing classifier with these extracted features, some well-known classifiers namely Support Vector Machine (SVM), Random Forest(RF), K-Nearest Neighbor, eXtreme Gradient Boosting(XGBoost) and Naive Bayes(NB) are trained and tested with the extracted features. It is found that SVM is outperforming other classifiers under some performance measuring metrics namely accuracy, precision, recall, False Alarm Rate(FAR),F1 value, and AUC value. Also, its performance is better than some other state-of-the art works so, it is selected for deployment in the SDN controller which can detect the attack in live traffic.
引用
收藏
页码:4268 / 4288
页数:21
相关论文
共 52 条
  • [1] Abdullah M., 2018, International Journal of Computer Science and Information Security IJCSIS, V16, P48
  • [2] An SVM-based framework for detecting DoS attacks in virtualized clouds under changing environment
    Abusitta, Adel
    Bellaiche, Martine
    Dagenais, Michel
    [J]. JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2018, 7
  • [3] Automated DDOS attack detection in software defined networking
    Ahuja, Nisha
    Singal, Gaurav
    Mukhopadhyay, Debajyoti
    Kumar, Neeraj
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 187 (187)
  • [4] Bandwidth Control Mechanism and Extreme Gradient Boosting Algorithm for Protecting Software-Defined Networks Against DDoS Attacks
    Alamri, Hassan A.
    Thayananthan, Vijey
    [J]. IEEE ACCESS, 2020, 8 : 194269 - 194288
  • [5] Feature Selection Using Information Gain for Improved Structural-Based Alert Correlation
    Alhaj, Taqwa Ahmed
    Siraj, Maheyzah Md
    Zainal, Anazida
    Elshoush, Huwaida Tagelsir
    Elhaj, Fatin
    [J]. PLOS ONE, 2016, 11 (11):
  • [6] Performance Analysis of POX and Ryu with Different SDN Topologies
    Ali, Jehad
    Lee, Seungwoon
    Roh, Byeong-hee
    [J]. PROCEEDINGS OF THE 2018 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND SYSTEM (ICISS 2018), 2018, : 244 - 249
  • [7] A Feature Selection Model for Network Intrusion Detection System Based on PSO, GWO, FFA and GA Algorithms
    Almomani, Omar
    [J]. SYMMETRY-BASEL, 2020, 12 (06): : 1 - 20
  • [8] POINTS OF SIGNIFICANCE Ensemble methods: bagging and random forests
    Altman, Naomi
    Krzywinski, Martin
    [J]. NATURE METHODS, 2017, 14 (10) : 933 - 934
  • [9] Banitalebi Dehkordi A, 2020, IEEE T IND APPL
  • [10] Bholebawa Idris Zoher, 2016, International Journal of Computer and Communication Engineering, V5, P419, DOI 10.17706/ijcce.2016.5.6.419-429