Detection of DDoS Attacks in Software Defined Networking Using Entropy

被引:19
|
作者
Fan, Cong [1 ,2 ]
Kaliyamurthy, Nitheesh Murugan [2 ]
Chen, Shi [1 ]
Jiang, He [1 ]
Zhou, Yiwen [1 ]
Campbell, Carlene [2 ]
机构
[1] Wuhan Univ Technol, Sch Informat Engn, Wuhan 430070, Peoples R China
[2] Univ Wales Trinity St David, Wales Inst Sci & Art, Swansea SA1 8PH, W Glam, Wales
来源
APPLIED SCIENCES-BASEL | 2022年 / 12卷 / 01期
关键词
software defined networking; entropy; distributed denial of service attacks; SECURITY ISSUES;
D O I
10.3390/app12010370
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Featured Application This study proposes a detection method of Distributed Denial of Service attacks in Software Defined Networking, which uses the property of entropy to measure the occurrence of attack behavior in the network. The significance of this study is to quickly and effectively detect Distributed Denial of Service attacks in the Software Defined Networking and protect the SDN controller against security threats. Software Defined Networking (SDN) is one of the most commonly used network architectures in recent years. With the substantial increase in the number of Internet users, network security threats appear more frequently, which brings more concerns to SDN. Distributed denial of Service (DDoS) attacks are one of the most dangerous and frequent attacks in software defined networks. The traditional attack detection method using entropy has some defects such as slow attack detection and poor detection effect. In order to solve this problem, this paper proposed a method of fusion entropy, which detects attacks by measuring the randomness of network events. This method has the advantages of fast attack detection speed and obvious decrease in entropy value. The complementarity of information entropy and log energy entropy is effectively utilized. The experimental results show that the entropy value of the attack scenarios 91.25% lower than normal scenarios, which has greater advantages and significance compared with other attack detection methods.
引用
收藏
页数:16
相关论文
共 50 条
  • [21] SDSNM: A Software-Defined Security Networking Mechanism to Defend against DDoS Attacks
    Wang, Xiulei
    Chen, Ming
    Xing, Changyou
    2015 NINTH INTERNATIONAL CONFERENCE ON FRONTIER OF COMPUTER SCIENCE AND TECHNOLOGY FCST 2015, 2015, : 115 - 121
  • [22] Effective software-defined networking controller scheduling method to mitigate DDoS attacks
    Yan, Q.
    Gong, Q.
    Yu, F. R.
    ELECTRONICS LETTERS, 2017, 53 (07) : 469 - 471
  • [23] Early Detection of DDoS Attacks Against Software Defined Network Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2018, 26 (03) : 573 - 591
  • [24] Early Detection of DDoS Attacks Against Software Defined Network Controllers
    Seyed Mohammad Mousavi
    Marc St-Hilaire
    Journal of Network and Systems Management, 2018, 26 : 573 - 591
  • [25] Improved Network Monitoring Using Software-Defined Networking for DDoS Detection and Mitigation Evaluation
    J. Ramprasath
    V. Seethalakshmi
    Wireless Personal Communications, 2021, 116 : 2743 - 2757
  • [26] Detecting Adversarial DDoS Attacks in Software-Defined Networking Using Deep Learning Techniques and Adversarial Training
    Nugraha, Beny
    Kulkarni, Naina
    Gopikrishnan, Akash
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 448 - 454
  • [27] Enhanced DDoS Detection Using Advanced Machine Learning and Ensemble Techniques in Software Defined Networking
    Butt, Hira Akhtar
    Al Harthy, Khoula Said
    Shah, Mumtaz Ali
    Hussain, Mudassar
    Amin, Rashid
    Rehman, Mujeeb Ur
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 81 (02): : 3003 - 3031
  • [28] Improved Network Monitoring Using Software-Defined Networking for DDoS Detection and Mitigation Evaluation
    Ramprasath, J.
    Seethalakshmi, V.
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 116 (03) : 2743 - 2757
  • [29] Software Defined Networking: Attacks and Countermeasures
    Abd Elazim, Nada Mostafa
    Sobh, Mohamed A.
    Bahaa-Eldin, Ayman M.
    PROCEEDINGS OF 2018 13TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND SYSTEMS (ICCES), 2018, : 555 - 567
  • [30] Inline detection of Denial of Service Attacks in Software Defined Networking using the Hotelling Chart
    Bensalah, Faycal
    Kamoun, Najib E. L.
    El Houssaini, Mohammed-Alamine
    10TH INT CONF ON EMERGING UBIQUITOUS SYST AND PERVAS NETWORKS (EUSPN-2019) / THE 9TH INT CONF ON CURRENT AND FUTURE TRENDS OF INFORMAT AND COMMUN TECHNOLOGIES IN HEALTHCARE (ICTH-2019) / AFFILIATED WORKOPS, 2019, 160 : 785 - 790