Entropy-based DoS Attack identification in SDN

被引:22
作者
Carvalho, Ranyelson N. [1 ]
Bordim, Jacir L. [1 ]
Alchieri, Eduardo A. P. [1 ]
机构
[1] Univ Brasilia UnB, Dept Comp Sci, Brasilia, DF, Brazil
来源
2019 IEEE INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM WORKSHOPS (IPDPSW) | 2019年
关键词
OPENFLOW;
D O I
10.1109/IPDPSW.2019.00108
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networks (SDN) represent a new network architecture that provides central control over the network. The main innovation behind an SDN network is that it decouples the data plane from the control plane, which defines a network programmable environment. In the control plane, the controller supports the execution of services that define the control policies and distributes these rules to the data plane through a standard protocol, such as OpenFlow. Despite the numerous benefits provided by this architecture, the security of an SDN network is still a matter of concern since the aforementioned decoupling increase the attack surface in the network. In fact, Denial of Service (DoS) attacks are the ones that challenge the SDN environments in many aspects, mainly due to vulnerabilities between the control and the data plane layers. Entropy-based DoS detection method is a technique widely used in conventional network architecture. This paper proposes the use of entropy in an SDN environment, through of the OpenFlow switches statistics, to build a mechanism that monitor the network and is able to differentiate DoS traffic from the benign traffic. Experimental results show the practical feasibility of the proposed solution.
引用
收藏
页码:627 / 634
页数:8
相关论文
共 28 条
[1]  
[Anonymous], 1980, RFC, DOI DOI 10.17487/RFC0768
[2]  
[Anonymous], 1981, 792 RFC
[3]  
Bani-Hani R., 2013, SYN FLOODING ATTACKS
[4]  
Bhandari Abhinav, 2015, International Journal of Computer Network and Information Security, V7, P9, DOI 10.5815/ijcnis.2015.08.02
[5]  
Casado M., 2010, WORKSH PROGR ROUT EX
[6]   AuthFlow: authentication and access control mechanism for software defined networking [J].
Ferrazani Mattos, Diogo Menezes ;
Muniz Bandeira Duarte, Otto Carlos .
ANNALS OF TELECOMMUNICATIONS, 2016, 71 (11-12) :607-615
[7]   OPERETTA: An OPEnflow-based REmedy to mitigate TCP SYNFLOOD Attacks against web servers [J].
Fichera, Silvia ;
Galluccio, Laura ;
Grancagnolo, Salvatore C. ;
Morabito, Giacomo ;
Palazzo, Sergio .
COMPUTER NETWORKS, 2015, 92 :89-100
[8]   Software-Defined Networking: A Comprehensive Survey [J].
Kreutz, Diego ;
Ramos, Fernando M. V. ;
Verissimo, Paulo Esteves ;
Rothenberg, Christian Esteve ;
Azodolmolky, Siamak ;
Uhlig, Steve .
PROCEEDINGS OF THE IEEE, 2015, 103 (01) :14-76
[9]   A Simple Detection Method for DoS Attacks based on IP Packets Entropy values [J].
Kurihara, Keiichirou ;
Katagishi, Kazuki .
2014 NINTH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIA JCIS), 2014, :44-51
[10]  
Lapolli AC, 2019, 2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM)