Applying NFV/SDN in Mitigating DDoS Attacks

被引:0
作者
Zhou, Luying [1 ]
Guo, Huaqun [1 ]
机构
[1] ASTAR, Inst Infocomm Res, Singapore, Singapore
来源
TENCON 2017 - 2017 IEEE REGION 10 CONFERENCE | 2017年
基金
新加坡国家研究基金会;
关键词
DDoS; Network Function Virtualization; Software-Defined Networking; Anomaly Detection; Attack Mitigation; Industry Control System;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Distributed Denial of Service (DDoS) is a widely employed attacking scheme over network that interrupts services by creating network congestion, draining server resources, or disabling normal functions of network components. An attacker launches the DDoS attack from a large number of compromised while geographically distributed devices by sending low rate seemly legitimate traffic that disturbs server's service, or high rate large volume traffic that overwhelms victim's processing capacity. DDoS attack mitigating approaches that apply pre-established defending strategy, functionality or capacity, and guard at fixed locations are costly and not effective either. Network Function Virtualization (NFV) supports the flexibility in on-demand function instantiation and allocation, and recently finds its applications in handling DDoS attacks. This paper proposes a NFV and Software-Defined Networking (SDN) enabled DDoS mitigation framework. In the framework, network traffic is monitored and analyzed utilizing the SDN features of central control and global network view, and the detection of anomaly traffic will trigger the actions of corresponding countermeasure computation, defending resources virtualization, instantiation, deployment and interconnection. The paper presents an application example of the proposed framework in protecting an industrial control system, and shows its effectiveness in mitigating DDoS attacks in the control system.
引用
收藏
页码:2061 / 2066
页数:6
相关论文
共 20 条
[1]  
Corero, SYN ACK FLOOD
[2]  
ETSI GS NFV-EVE, 2015, NETW FUNCT VIRT NFV
[3]  
ETSI-GS-NFV, 2013, NETW FUNCT VIRT NFV
[4]  
Fayaz SK, 2015, PROCEEDINGS OF THE 24TH USENIX SECURITY SYMPOSIUM, P817
[5]  
Fung CJ, 2015, INT CONF NETW SER, P64, DOI 10.1109/CNSM.2015.7367340
[6]  
Futamura K, 2015, 2015 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORK (NFV-SDN), P170, DOI 10.1109/NFV-SDN.2015.7387423
[7]   DDOS Mitigation Cloud-Based Service [J].
Guenane, Fouad ;
Nogueira, Michele ;
Serhrouchni, Ahmed .
2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, :1363-1368
[8]  
Han B., 2015, NETWORK FUNCTIONS VI
[9]  
Hoque N., 2015, IEEE COMMUNICATION S, V17
[10]  
Incapsula, TCP SYN FLOOD DDOS A