Detection and Analysis of TCP-SYN DDoS Attack in Software-Defined Networking

被引:26
作者
Swami, Rochak [1 ]
Dave, Mayank [1 ]
Ranga, Virender [1 ]
机构
[1] Natl Inst Technol, Dept Comp Engn, Kurukshetra 136119, Haryana, India
关键词
SDN; DDoS; IDS; Machine learning; DETECTION SYSTEMS; SDN; CHALLENGES;
D O I
10.1007/s11277-021-08127-6
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software-defined networking (SDN) is an advanced networking technology that yields flexibility with cost-efficiency as per the business requirements. SDN breaks the vertical integration of control and data plane and promotes centralized network management. SDN allows data intensive applications to work more efficiently by making the network dynamically configurable. With the growing development of SDN technology, the issue of security becomes critical because of its architectural characteristics. Currently, Distributed denial of service (DDoS) is one of the most powerful attacks that cause the services to be unavailable for normal users. DDoS seeks to consume the resources of the SDN controller with the intention to slow down working of the network. In this paper, a detailed analysis of the effect of spoofed and non-spoofed TCP-SYN flooding attacks on the controller resources in SDN is presented. We also suggest a machine learning based intrusion detection system. Five different classification models belong to a variety of families are used to classify the traffic, and evaluated using different performance indicators. Cross-validation technique is used to validate the classification models. This work enables better features to be extracted and classify the traffic efficiently. The experimental results reveal significantly good performance with all the considered classification models.
引用
收藏
页码:2295 / 2317
页数:23
相关论文
共 56 条
  • [1] [Anonymous], 2017, NSL KDD DATASET
  • [2] [Anonymous], 2018, CICIDS2017 DATASET
  • [3] [Anonymous], 2017, UNSW NB15 DATASET
  • [4] [Anonymous], 2016, 2016 dyn cyberattack
  • [5] [Anonymous], 1988, TCPDUMP
  • [6] [Anonymous], 2008, SCAPY
  • [7] [Anonymous], 2018, ARBOR NETWORKS
  • [8] [Anonymous], 2018, BIGGEST DDOS ATTACKS
  • [9] [Anonymous], 2016, CORR
  • [10] [Anonymous], MACH LEARN