Distributed-SOM: A novel performance bottleneck handler for large-sized software-defined networks under flooding attacks

被引:25
作者
Phan, Trung V. [1 ]
Nguyen Khac Bao [1 ]
Park, Minho [1 ]
机构
[1] Soongsil Univ, Dept ICMC Convergence Technol, Seoul 156743, South Korea
关键词
Flooding attacks; Distributed denial-of-service; Self-organizing map; Software-defined networks;
D O I
10.1016/j.jnca.2017.04.016
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking (SDN) is a new programmable networking model that features the detachment of control and data planes. In this network, the network brain is an SDN controller that is used to centrally monitor and control the data plane based on the OpenFlow protocol and applications located in the application layer. In recent years, a vast number of issues relating to security have been seriously debated for this networking paradigm, especially the large-scale model. In particular, flooding attacks have been on the rise, providing great challenges for the SDN architecture to cope with. In this paper, we present a novel mechanism using the Self Organizing Map (SOM) application to solve the performance bottleneck and overload problems for the upper layers in a large-sized SDN in case of flooding attacks. Our proposed approach integrates a Distributed Self Organizing Map (DSOM) system to OpenFlow Switches instead of using a standalone SOM. By exploiting SDN advantages, such as flexibility and overhead reduction, we implement and test both a DSOM system and a single SOM system on multi-criteria to compare the performance of our introduced system. Our experimental results show that the DSOM solution can effectively detect abnormal traffic, solve bottleneck problems and increase the system reaction speed to attack traffic, while presenting a smaller overhead to the network system.
引用
收藏
页码:14 / 25
页数:12
相关论文
共 45 条
[1]  
Alsulaiman MM, 2009, NSS: 2009 3RD INTERNATIONAL CONFERENCE ON NETWORK AND SYSTEM SECURITY, P397, DOI 10.1109/NSS.2009.62
[2]  
[Anonymous], P 2014 6 INT C NEW T, DOI DOI 10.1109/NTMS.2014.6814019
[3]  
[Anonymous], 2017, FLOODLIGHT IS OPEN S
[4]  
[Anonymous], 2015, TECHNICAL REPORT
[5]  
[Anonymous], 2009, NSL KDD DATA SET NET
[6]  
[Anonymous], 2010, OSDI
[7]  
[Anonymous], EUR NETFPGA DEV WORK
[8]  
[Anonymous], 2017, OMNIPEEK NETWORK ANA
[9]  
Braga R, 2010, C LOCAL COMPUT NETW, P408, DOI 10.1109/LCN.2010.5735752
[10]  
CAIDA Datasets, DDOS ATT 2007