Self-healing topology for DDoS attack identification & discovery protocol in software-defined networks

被引:9
|
作者
Sharma, Gajanand [1 ]
Sharma, Himanshu [1 ]
Pareek, Rajneesh [1 ]
Gour, Nidhi [1 ]
Sharma, Ravi Shanker [1 ]
Kumar, Ashutosh [1 ]
机构
[1] JECRC Univ, Dept Comp Sci & Engn, Jaipur 303905, Rajasthan, India
关键词
SDN; Dos attack; Open flow; Accuracy; HyPASS. POX & RYU; PACKET INJECTION ATTACK;
D O I
10.1080/09720529.2021.2009192
中图分类号
O29 [应用数学];
学科分类号
070104 ;
摘要
Software defined networking is an emerging network architecture that separates the control plane from the data plane of network devices and places the control plane on one or more control servers capable of managing the rules traffic forwarding of all communication devices under your domain. This article describes the architecture, different modules, and event sequences of the HyPASS for real-time protection from address-forged attacks with proactive host discovery and address validation. Such attacks cause the wastage of network bandwidth, processing power, and network resources available to the user. We performed the latency, throughput, and attack prevention tests using POX & RYU controllers on the Mininet network simulator with and without HyPASS. The system performance is analyzed for accuracy and efficiency in four different SDN scenarios categorized as fully OpenFlow enabled and Hybrid. The proposed system discovers all the live hosts in the network, updates Host Table at the handshaking between controller and OpenFlow switches. Experiments show that the system prevented all the address-forged attacks by validating the source address in different SDN environments. It achieves a 99.99% filtering accuracy level in a fully OpenFlow-enabled setup.
引用
收藏
页码:2221 / 2232
页数:12
相关论文
共 50 条
  • [31] Modeling and verifying the topology discovery mechanism of OpenFlow controllers in software-defined networks using process algebra
    Xiang, Shuangqing
    Zhu, Huibiao
    Wu, Xi
    Xiao, Lili
    Bonsangue, Marcello
    Xie, Wanling
    Zhang, Lei
    SCIENCE OF COMPUTER PROGRAMMING, 2020, 187
  • [32] Deep Learning Models Comparison in binary context for DDoS Attack Detection in Software-Defined Network
    Zaidoun, Ameur Salem
    Lachiri, Zied
    2024 IEEE 7TH INTERNATIONAL CONFERENCE ON ADVANCED TECHNOLOGIES, SIGNAL AND IMAGE PROCESSING, ATSIP 2024, 2024, : 105 - 109
  • [33] Zero-Day Attack Detection and Prevention in Software-Defined Networks
    Al-Rushdan, Huthifh
    Shurman, Mohammad
    Alnabelsi, Sharhabeel H.
    Althebyan, Qutaibah
    2019 INTERNATIONAL ARAB CONFERENCE ON INFORMATION TECHNOLOGY (ACIT), 2019, : 278 - 282
  • [34] A Table Overflow LDoS Attack Defending Mechanism in Software-Defined Networks
    Xie, Shengxu
    Xing, Changyou
    Zhang, Guomin
    Zhao, Jinlong
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [35] Deep Reinforcement Learning based Smart Mitigation of DDoS Flooding in Software-Defined Networks
    Liu, Yandong
    Dong, Mianxiong
    Otat, Kaoru
    Li, Jianhua
    Wu, Jun
    2018 IEEE 23RD INTERNATIONAL WORKSHOP ON COMPUTER AIDED MODELING AND DESIGN OF COMMUNICATION LINKS AND NETWORKS (CAMAD), 2018, : 80 - 85
  • [36] Investigation of application layer DDoS attacks in legacy and software-defined networks: A comprehensive review
    Kaur, Sarabjeet
    Sandhu, Amanpreet Kaur
    Bhandari, Abhinav
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (06) : 1949 - 1988
  • [37] MIND: Message Classification Based Controller Scheduling Method for Resisting DDoS Attack in Software-Defined Networking
    Cui, Yunhe
    Qian, Qing
    2020 5TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2020), 2020, : 486 - 490
  • [38] Machine Learning Approach Equipped with Neighbourhood Component Analysis for DDoS Attack Detection in Software-Defined Networking
    Tonkal, Ozgur
    Polat, Huseyin
    Basaran, Erdal
    Comert, Zafer
    Kocaoglu, Ramazan
    ELECTRONICS, 2021, 10 (11)
  • [39] Self-Modeling Based Diagnosis of Software-Defined Networks
    Sanchez, Jose Manuel
    Ben Yahia, Imen Grida
    Crespi, Noel
    2015 1ST IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT), 2015,
  • [40] A Deep CNN Ensemble Framework for Efficient DDoS Attack Detection in Software Defined Networks
    Haider, Shahzeb
    Akhunzada, Adnan
    Mustafa, Iqra
    Patel, Tanil Bharat
    Fernandez, Amanda
    Choo, Kim-Kwang Raymond
    Iqbal, Javed
    IEEE ACCESS, 2020, 8 : 53972 - 53983