DDOS Attack Detection & Prevention in SDN using OpenFlow Statistics

被引:0
|
作者
Ahuja, Nisha [1 ]
Singal, Gaurav [1 ]
机构
[1] Bennett Univ, Dept CSE, Greater Noida, India
关键词
SDN; Mininet; Network attack; Traffic simulation; DDOS;
D O I
10.1109/iacc48062.2019.8971596
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Software defined Network is a network defined by software, which is one of the important feature which makes the legacy old networks to be flexible for dynamic configuration and so can cater to today's dynamic application requirement. It is a programmable network but it is prone to different type of attacks due to its centralized architecture. The author provided a solution to detect and prevent Distributed Denial of service attack in the paper. Mininet [5] which is a popular emulator for Software defined Network is used. We followed the approach in which collection of the traffic statistics from the various switches is done. After collection we calculated the packet rate and bandwidth which shoots up to high values when attack take place. The abrupt increase detects the attack which is then prevented by changing the forwarding logic of the host nodes to drop the packets instead of forwarding. After this, no more packets will be forwarded and then we also delete the forwarding rule in the flow table. Hence, we are finding out the change in packet rate and bandwidth to detect the attack and to prevent the attack we modify the forwarding logic of the switch flow table to drop the packets coming from malicious host instead of forwarding it.
引用
收藏
页码:147 / 152
页数:6
相关论文
共 50 条
  • [21] Efficient Joint Detection and Defense Mechanism for DDoS Attack in SDN
    Zeng R.-F.
    Gao Y.
    Wang X.-W.
    Zhang B.
    Dongbei Daxue Xuebao/Journal of Northeastern University, 2020, 41 (09): : 1217 - 1222
  • [22] A Research Review on SDN-Based DDOS Attack Detection
    Zhu, Weidong
    Yi, Xiujuan
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND MANAGEMENT INNOVATION (MSMI 2017), 2017, 31 : 145 - 149
  • [23] A New Framework for DDoS Attack Detection and Defense in SDN Environment
    Tan, Liang
    Pan, Yue
    Wu, Jing
    Zhou, Jianguo
    Jiang, Hao
    Deng, Yuchuan
    IEEE ACCESS, 2020, 8 : 161908 - 161919
  • [24] A CGAN-based DDoS Attack Detection Method in SDN
    Liu
    Luo
    Jiang
    Wang
    Li
    Jia
    IWCMC 2021: 2021 17TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2021, : 1030 - 1034
  • [25] Detection of Control Layer DDoS Attack using Entropy metrics in SDN: An Empirical Investigation
    Sahoo, Kshira Sagar
    Sahoo, Bibhudatta
    Vankayala, Manikanta
    Dash, Ratnakar
    2017 NINTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC), 2017, : 281 - 286
  • [26] A DDoS attack detection and defense scheme using time-series analysis for SDN
    Fouladi, Ramin Fadaei
    Ermis, Orhan
    Anarim, Emin
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 54 (54)
  • [27] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    M. Revathi
    V. V. Ramalingam
    B. Amutha
    Wireless Personal Communications, 2022, 127 (3) : 2417 - 2441
  • [28] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    Revathi, M.
    Ramalingam, V. V.
    Amutha, B.
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (03) : 2417 - 2441
  • [29] DDoS attack identification based on SDN
    Dobrin, Dobrev
    Dimiter, Avresky
    2021 IEEE 20TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2021,
  • [30] Mitigation of DDoS Attack Using Moving Target Defense in SDN
    Rochak Swami
    Mayank Dave
    Virender Ranga
    Wireless Personal Communications, 2023, 131 : 2429 - 2443