Mitigating Crossfire Attacks using SDN-based Moving Target Defense

被引:53
作者
Aydeger, Abdullah [1 ]
Saputro, Nico [1 ]
Akkaya, Kemal [1 ]
Rahman, Mohammad [2 ]
机构
[1] Florida Int Univ, Dept Elect & Comp Engn, Miami, FL 33174 USA
[2] Tennessee Technol Univ, Dept Comp Sci, Cookeville, TN 38505 USA
来源
2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN) | 2016年
关键词
Software Defined Networking; Moving Target Defense; crossfire DDoS attacks; route mutation; data delay;
D O I
10.1109/LCN.2016.108
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Recent research demonstrated that software defined networking (SDN) can be leveraged to enable moving target defense (MTD) to mitigate distributed denial of service (DDoS) attacks. The network states are continuously changed in MTD by effectively collecting information from the network and enforcing certain security measures on the fly in order to deceive the attackers. Being motivated from the success of SDN-based maneuvering, this work targets an emerging type of DDoS attacks, called Crossfire, and proposes an SDN-based MTD mechanism to defend against such attacks. We analyze Crossfire attack planning and utilize the analyzed results to develop the defense mechanism which in turn reorganize the routes in such a way that the congested links are avoided during packet forwarding. The detection and mitigation techniques are implemented using Mininet emulator and Floodlight SDN controller. The evaluation results show that the route mutation can effectively reduce the congestion in the targeted links without making any major disruption on network services.
引用
收藏
页码:627 / 630
页数:4
相关论文
共 16 条
[1]  
A. Networks, 2014, 10 ANN WORLDW INFR S
[2]  
[Anonymous], 2014, Proceedings of the IEEE International Symposium on a World of Wireless, Mobile and Multimedia Networks WoWMoM, DOI DOI 10.1109/WOWMOM.2014.6918979
[3]  
Carroll TE, 2014, IEEE ICC, P701, DOI 10.1109/ICC.2014.6883401
[4]  
Chavez AR, 2015, INT CARN CONF SECU, P77
[5]  
Hirasawa T., 2015, INT TOP M MICR PHOT, P1
[6]  
Incapsula, 2014, WHAT DDOS ATT REALL
[7]   An Effective Address Mutation Approach for Disrupting Reconnaissance Attacks [J].
Jafarian, Jafar Haadi ;
Al-Shaer, Ehab ;
Duan, Qi .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2015, 10 (12) :2562-2577
[8]  
Jafarian JH, 2012, P 1 WORKSH HOT TOP S, P127, DOI DOI 10.1145/2342441.2342467
[9]   The Crossfire Attack [J].
Kang, Min Suk ;
Lee, Soo Bum ;
Gligor, Virgil D. .
2013 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2013, :127-141
[10]   CoDef: Collaborative Defense Against Large-Scale Link-Flooding Attacks [J].
Lee, Soo Bum ;
Kang, Min Suk ;
Gligor, Virgil D. .
PROCEEDINGS OF THE 2013 ACM INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES (CONEXT '13), 2013, :417-427