SDN-based DDoS Attack Detection with Cross-Plane Collaboration and Lightweight Flow Monitoring

被引:0
作者
Yang, Xiangrui [1 ]
Han, Biao [1 ]
Sun, Zhigang [1 ]
Huang, Jinfeng [1 ]
机构
[1] Natl Univ Def Technol, Sch Comp, Changsha, Hunan, Peoples R China
来源
GLOBECOM 2017 - 2017 IEEE GLOBAL COMMUNICATIONS CONFERENCE | 2017年
基金
美国国家科学基金会;
关键词
DDoS Attack Detection; OpenFlow switch; Software Defined Networking; Cross-Plane Collaboration;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Distributed Denial of Service (DDoS) attack is one of the biggest concerns for security professionals. Traditional DDoS attack detection mechanisms are based on middle-box devices or SDN controllers, which either lack network-wide monitoring information or suffer with serious southbound communication overhead and detection delay. In this paper, we propose a SDN-based DDoS attack detection framework with cross-plane collaboration called OverWatch, which performs a two-stage granularity filtering procedure between coarse-grained detection data plane and fine-grained detection control plane for abnormal flows. It leverages computational capabilities that currently underutilized on OpenFlow switches to shrink the detection range for fine-grained DDoS attack detections. In OverWatch, we propose a lightweight flow monitoring algorithm to capture the key features of DDoS attack traffics on the data plane by polling the values of counters in OpenFlow switches. Experiments are conducted in an evaluating network with a FPGA-based OpenFlow switch prototype and the Ryu controller, which reveal that our proposed OverWatch framework and flow monitoring algorithm can greatly improve the detection efficiency, as well as reduce the detection delay and southbound communication overhead.
引用
收藏
页数:6
相关论文
共 13 条
[1]  
[Anonymous], 2014, OPENFLOW SWITCH SPEC
[2]  
[Anonymous], 2016, P 2016 NETW DISTR SY
[3]  
Braga Rodrigo, 2010, LOC COMP NETW LCN 20
[4]  
Chowdhury Shihabur Rahman, 2014, NETW OP MAN S NOMS 2
[5]  
Claise B., CISCO SYSTEMS NETFLO
[6]  
Hping3, 2005, HPING3 8 LIN MAN PAG
[7]  
Mai J., 2006, P 6 ACM SIGCOMM C IN
[8]   Efficient mismatched packet buffer management with packet order-preserving for OpenFlow networks [J].
Mao, Jianbiao ;
Han, Biao ;
Sun, Zhigang ;
Lu, Xicheng ;
Zhang, Ziwen .
COMPUTER NETWORKS, 2016, 110 :91-103
[9]  
Shin S., 2013, P 2013 ACM SIGSAC C
[10]  
Tomonori F, 2013, Introduction to ryu sdn framework