Entropy based mitigation of Distributed-Denial-of-Service (DDoS) attack on Control Plane in Software-Defined-Network (SDN)

被引:0
作者
Yadav, Sanjay Kumar [1 ]
Suguna, P. [1 ]
Velusamy, R. Leela [1 ]
机构
[1] Natl Inst Technol, Comp Sci & Engn, Tiruchirappalli 620015, India
来源
2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT) | 2019年
关键词
SDN; Data plane; Control plane; Centralized control; DDoS; Attack; Vulnerabilities; Mitigation; Entropy;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN is new networking concept which has revolutionized the network architecture in recent years. It decouples control plane from data plane. Architectural change provides re- programmability and centralized control management of the network. At the same time it also increases the complexity of underlying physical infrastructure of the network. Unfortunately, the centralized control of the network introduces new vulnerabilities and attacks. Attackers can exploit the limitation of centralized control by DDoS attack on control plane. The entire network can be compromised by DDoS attack. Based on packet entropy, a solution for mitigation of DDoS attack provided in the proposed scheme.
引用
收藏
页数:7
相关论文
共 15 条
[1]  
Belyaev M., 2014, P INT SCI TECHN C MO
[2]  
Buragohain Chaitanya, 2016, 2016 3rd International Conference on Signal Processing and Integrated Networks (SPIN), P519, DOI 10.1109/SPIN.2016.7566750
[3]   Collaborative detection of DDoS attacks over multiple network domains [J].
Chen, Yu ;
Hwang, Kai ;
Ku, Wei-Shinn .
IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2007, 18 (12) :1649-1662
[4]  
Fonseca P, 2012, IEEE IFIP NETW OPER, P933, DOI 10.1109/NOMS.2012.6212011
[5]  
Guang Yao, 2011, 2011 19th IEEE International Conference on Network Protocols, P7, DOI 10.1109/ICNP.2011.6089085
[6]   SDN-Assisted Slow HTTP DDoS Attack Defense Method [J].
Hong, Kiwon ;
Kim, Youngjun ;
Choi, Hyungoo ;
Park, Jinwoo .
IEEE COMMUNICATIONS LETTERS, 2018, 22 (04) :688-691
[7]  
Hu Y., 2013, IEEE INT C DEP SYST, P1, DOI 10.1109/IVEC.2013.6570931
[8]   Secure and Efficient Initialization and Authentication Protocols for SHIELD [J].
Jin, Chenglu ;
van Dijk, Marten .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (01) :156-173
[9]   SLICOTS: An SDN-Based Lightweight Countermeasure for TCP SYN Flooding Attacks [J].
Mohammadi, Reza ;
Javidan, Reza ;
Conti, Mauro .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (02) :487-497
[10]  
Mutu L, 2015, IEEE CONF COMM NETW, P715, DOI 10.1109/CNS.2015.7346900