A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework

被引:20
作者
Revathi, M. [1 ]
Ramalingam, V. V. [1 ]
Amutha, B. [1 ]
机构
[1] SRM Inst Sci & Technol, Dept Comp Sci & Engn, Kattankulathur 603203, India
关键词
Software-defined networking; DDoS attack; Spark standardization technique; Semantic multilinear component analysis; Discrete scalable memory based support vector machine algorithm; Mininet; RYU controller;
D O I
10.1007/s11277-021-09071-1
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Recently, SDN has arisen as a new network platform that offers unparalleled programming that enables network operators to dynamically customize and control their networks. The attackers aim to paralyse the logical plane, the brain of the network that offers several advantages, by using the SDN controller. However, the control plane is the desirable target of security attacks on the opponents because of its characteristics. One of the most common threats is the DDOS attacks to drain network capacity by sending them heavy traffic, causing network congestion. SDN is a common area of investigation for SDN defenceand DDoS threat identification and prevention in the SDN context has been introduced to many researchers since the proposed SDN attacks. Nevertheless, security risks must be adequately secured. In this paper we suggest a discrete scalable memory based support vector machine algorithm for DDoS threat and SDN mitigation architecture for attack detection. By starting the process of attack detection the input data can gets pre-processed by using Spark standardization technique in which the missing values are replaced and the unwanted data are removed. Then the feature extractions are done using semantic multilinear component analysis algorithm. The classifier is responsible for predicting target and for this a novel discrete scalable memory based support vector machine (DSM-SVM) algorithm is used which provides high accuracy of attack prediction. Followed by attack detection the mitigation process was done, here the mitigation server can identify the threat by intelligently dropping malicious bot traffic and absorbing the rest of the traffic. Here the suggested mechanism achieves attack traffic mitigation and benign traffic dropping. We have evaluated the whole process on KDD dataset. The proposed network model was trained and then used in an SDN threat detection and mitigation environment as part of the assessment process. The entire experiment is run on a VMware-based Ubuntu virtual machine. Weka will utilize our suggested classifier model for training and evaluation, while Mininet uses a RYU controller to establish an SD Network. The findings demonstrate that the mechanism presented exceeds the other algorithms examined, by expressing 99.7% accuracy especially concerning training and testing time over KDD dataset.
引用
收藏
页码:2417 / 2441
页数:25
相关论文
共 39 条
  • [1] Abdelmoniem A. M., 2016, HKUSTCS1601 CSE DEPT
  • [2] Using discriminant analysis to detect intrusions in external communication for self-driving vehicles
    Alheeti, Khattab M. Ali
    Gruebler, Anna
    McDonald-Maier, Klaus
    [J]. DIGITAL COMMUNICATIONS AND NETWORKS, 2017, 3 (03) : 180 - 187
  • [3] Detecting and Mitigating DDoS Attack in Named Data Networking
    Alhisnawi, Mohammad
    Ahmadi, Mahmood
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (04) : 1343 - 1365
  • [4] Alshamrani A., 2017, P 15 ACM INT S MOBIL, P83
  • [5] A Flexible SDN-Based Architecture for Identifying and Mitigating Low-Rate DDoS Attacks Using Machine Learning
    Arturo Perez-Diaz, Jesus
    Amezcua Valdovinos, Ismael
    Choo, Kim-Kwang Raymond
    Zhu, Dakai
    [J]. IEEE ACCESS, 2020, 8 (08): : 155859 - 155872
  • [6] DDoS Attack Detection and Mitigation Using SDN: Methods, Practices, and Solutions
    Bawany, Narmeen Zakaria
    Shamsi, Jawwad A.
    Salah, Khaled
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2017, 42 (02) : 425 - 441
  • [7] Buber E., 2017, INT C INT SYST DES A, P608
  • [8] Machine learning based low-rate DDoS attack detection for SDN enabled IoT networks
    Cheng, Haosu
    Liu, Jianwei
    Xu, Tongge
    Ren, Bohan
    Mao, Jian
    Zhang, Wei
    [J]. INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2020, 34 (01) : 56 - 69
  • [9] Deepa V., 2018, 2018 International Conference on Smart Systems and Inventive Technology (ICSSIT), P299, DOI 10.1109/ICSSIT.2018.8748836
  • [10] Enhanced transductive support vector machine classification with grey wolf optimizer cuckoo search optimization for intrusion detection system
    Devi, E. M. Roopa
    Suganthe, R. C.
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (04)