FMD: A DoS mitigation scheme based on flow migration in software-defined networking

被引:12
作者
Wu, Pengpeng [1 ,2 ]
Yao, Lin [1 ,2 ]
Lin, Chi [1 ,2 ]
Wu, Guowei [1 ,2 ]
Obaidat, Mohammad S. [3 ]
机构
[1] Dalian Univ Technol, Sch Software, Dalian 116620, Liaoning, Peoples R China
[2] Key Lab Ubiquitous Network & Serv Software Liaoni, Dalian, Peoples R China
[3] Monmouth Univ, Dept Comp Sci & Software Engn, Long Branch, NJ 07764 USA
基金
中国国家自然科学基金;
关键词
attack mitigation; denial of service attack; OpenFlow; software-defined networking; ATTACKS;
D O I
10.1002/dac.3543
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Software-defined networking (SDN) emerges as the next generation of networking architecture, aiming to improve the network manageability and adaptability. However, because of the centralized control policy, SDN is liable to suffering from the denial of service attack in both the data plane and the control plane. To resist the attack and prevent the network from being paralyzed, we propose a novel mitigation scheme named flow migration defense, which uses a slave controller as a substitution to endure flooding requests mitigated from the master controller. Considering the special case that the normal requests may be regarded as the malicious ones, these requests are reforwarded back to the master controller on the basis of the round-robin scheduling. To prevent the master controller from being flooded by the reforwarded requests, we design the adaptive rate adjustment method to adjust the reforwarding rate. Compared with multilevel feedback queue and FloodDefender, simulations demonstrate that flow migration defense can mitigate the SDN-aimed denial of service attack efficiently with a better performance in terms of request response time, packet loss rate, and mitigation time.
引用
收藏
页数:14
相关论文
共 23 条
[1]   Security in Software Defined Networks: A Survey [J].
Ahmad, Ijaz ;
Namal, Suneth ;
Ylianttila, Mika ;
Gurtov, Andrei .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04) :2317-2346
[2]   LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined Networking [J].
Ambrosin, Moreno ;
Conti, Mauro ;
De Gaspari, Fabio ;
Poovendran, Radha .
IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (02) :1206-1219
[3]  
Ambrosin Moreno., 2016, New Technologies, Mobility and Security (NTMS), 2016 8th IFIP International Conference on, P1
[4]  
[Anonymous], 2017, IEEE INFOCOM 2017-IEEE Conference on Computer Communications
[5]  
Chen KY, 2016, IEEE CONF COMM NETW, P28, DOI 10.1109/CNS.2016.7860467
[6]   SDN-Guard: DoS Attacks Mitigation in SDN Networks [J].
Dridi, Lobna ;
Zhani, Mohamed Faten .
2016 5TH IEEE INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (IEEE CLOUDNET), 2016, :212-217
[7]   Software-Defined Networking: A survey [J].
Farhady, Hamid ;
Lee, HyunYong ;
Nakao, Akihiro .
COMPUTER NETWORKS, 2015, 81 :79-95
[8]   A survey on OpenFlow-based Software Defined Networks: Security challenges and countermeasures [J].
Li, Wenjuan ;
Meng, Weizhi ;
Kwok, Lam For .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 68 :126-139
[9]   Controller scheduling for continued SDN operation under DDoS attacks [J].
Lim, Sungheon ;
Yang, Seungnam ;
Kim, Younghwa ;
Yang, Sunhee ;
Kim, Hyogon .
ELECTRONICS LETTERS, 2015, 51 (16) :1259-1260
[10]   OpenFlow: Enabling innovation in campus networks [J].
McKeown, Nick ;
Anderson, Tom ;
Balakrishnan, Hari ;
Parulkar, Guru ;
Peterson, Larry ;
Rexford, Jennifer ;
Shenker, Scott ;
Turner, Jonathan .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2008, 38 (02) :69-74