Mitigating DDoS Attacks Using OpenFlow-Based Software Defined Networking

被引:3
|
作者
Jonker, Mattijs [1 ]
Sperotto, Anna [1 ]
机构
[1] Univ Twente, CTIT, DACS, NL-7500 AE Enschede, Netherlands
来源
INTELLIGENT MECHANISMS FOR NETWORK CONFIGURATION AND SECURITY | 2015年 / 9122卷
关键词
D O I
10.1007/978-3-319-20034-7_13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the last years, Distributed Denial-of-Service (DDoS) attacks have become an increasing threat on the Internet, with recent attacks reaching traffic volumes of up to 500 Gbps. To make matters worse, web-based facilities that offer "DDoS-as-a-service" (i.e., Booters) allow for the layman to launch attacks in the order of tens of Gbps in exchange for only a few euros. A recent development in networking is the principle of Software Defined Networking (SDN), and related technologies such as OpenFlow. In SDN, the control plane and data plane of the network are decoupled. This has several advantages, such as centralized control over forwarding decisions, dynamic updating of forwarding rules, and easier and more flexible network configuration. Given these advantages, we expect SDN to be well-suited for DDoS attack mitigation. Typical mitigation solutions, however, are not built using SDN. In this paper we propose to design and to develop an OpenFlow-based mitigation architecture for DDoS attacks. The research involves looking at the applicability of OpenFlow, as well as studying existing solutions built on other technologies. The research is as yet in its beginning phase and will contribute towards a Ph.D. thesis after four years.
引用
收藏
页码:129 / 133
页数:5
相关论文
共 50 条
  • [1] A Novel OpenFlow-Based DDoS Flooding Attack Detection and Response Mechanism in Software-Defined Networking
    Wang, Rui
    Zhang, Zhiyong
    Ju, Lei
    Jia, Zhiping
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2015, 9 (03) : 21 - 40
  • [2] A Secured OpenFlow-Based Software Defined Networking Using Dynamic Bayesian Network
    Sophakan, Natnaree
    Sathitwiriyawong, Chanboon
    2019 19TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION AND SYSTEMS (ICCAS 2019), 2019, : 1517 - 1522
  • [3] Lightweight Automatic Discovery Protocol for OpenFlow-Based Software Defined Networking
    Jia, Yongzhe
    Xu, Lei
    Yang, Yuwang
    Zhang, Xiaoling
    IEEE COMMUNICATIONS LETTERS, 2020, 24 (02) : 312 - 315
  • [4] Detection of DDoS Attacks in Software Defined Networking Using Entropy
    Fan, Cong
    Kaliyamurthy, Nitheesh Murugan
    Chen, Shi
    Jiang, He
    Zhou, Yiwen
    Campbell, Carlene
    APPLIED SCIENCES-BASEL, 2022, 12 (01):
  • [5] Mitigating DNS Query-Based DDoS Attacks with Machine Learning on Software-Defined Networking
    Ahmed, Muhammad Ejaz
    Kim, Hyoungshick
    Park, Moosung
    MILCOM 2017 - 2017 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2017, : 11 - 16
  • [6] OpenFlow-Based Mobility Management Scheme and Data Structure for the Mobility Service at Software Defined Networking
    Park, Pill-Won
    Kim, Seong-Mun
    Min, Sung-Gi
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2016,
  • [7] Efficient topology discovery in OpenFlow-based Software Defined Networks
    Pakzad, Farzaneh
    Portmann, Marius
    Tan, Wee Lum
    Indulska, Jadwiga
    COMPUTER COMMUNICATIONS, 2016, 77 : 52 - 61
  • [8] Bringing Intelligence to Software Defined Networks: Mitigating DDoS Attacks
    Houda, Zakaria Abou El
    Khoukhi, Lyes
    Hafid, Abdelhakim Senhaji
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (04): : 2523 - 2535
  • [9] Performances of OpenFlow-Based Software-Defined Networks: An overview
    Benamrane, Fouad
    Ben Mamoun, Mouad
    Benaini, Redouane
    JOURNAL OF NETWORKS, 2015, 10 (06) : 329 - 337
  • [10] Modeling and Verifying TopoGuard in OpenFlow-Based Software Defined Networks
    Xiang, Shuangqing
    Zhu, Huibiao
    Xiao, Lili
    Xie, Wanling
    PROCEEDINGS 2018 12TH INTERNATIONAL SYMPOSIUM ON THEORETICAL ASPECTS OF SOFTWARE ENGINEERING (TASE 2018), 2018, : 84 - 91