Discriminate, locate and mitigate DDoS traffic in presence of Flash Crowd in Software Defined Network

被引:2
作者
Patil, Jitendra [1 ]
Tokekar, Vrinda [2 ]
Rajan, Alpana [1 ]
Rawat, Anil [1 ]
机构
[1] Raja Ramanna Ctr Adv Technol, Indore 13, India
[2] Devi Ahilya Vishwavidyalaya, Inst Engn & Technol, Indore 17, India
关键词
DDoS; Legitimate IP; Spoof IP; Flash crowd; ATTACKS; OPENFLOW;
D O I
10.1007/s11227-022-04538-9
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Discrimination of Flash crowd and Distributed Denial of Service (DDoS) traffic has been addressed already in legacy network and Software Defined Network (SDN), and remains a challenging task. The nature of Flash crowd and DDoS traffic is similar and becomes more complex to identify when DDoS traffic is generated from legitimate IPs of compromised hosts. Mostly, the works available in the literature are based on Entropy or Machine Learning or Deep Learning techniques to address this complex problem. The accuracy of these techniques depend on features available in datasets, which may vary from network to network. In this paper, our contribution is to devise a model based on behavior and techniques used by attackers to generate Multi-Destination (MD) DDoS traffic targeting SDN controllers. The novelty of the proposed model is to detect, locate, and mitigate MD spoof source IP/MAC and also contribute to defending malicious traffic generated using legitimate IP/MAC addresses.
引用
收藏
页码:16770 / 16793
页数:24
相关论文
共 34 条
[1]  
Agarwal S, 2013, P IEEE INFOCOM
[2]   Automated DDOS attack detection in software defined networking [J].
Ahuja, Nisha ;
Singal, Gaurav ;
Mukhopadhyay, Debajyoti ;
Kumar, Neeraj .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 187 (187)
[3]  
[Anonymous], 2016, MULTIMED TOOLS APPL
[4]  
Braga R, 2010, P C LOC COMP NETW LC
[5]   Selective Packet Inspection to Detect DoS Flooding Using Software Defined Networking (SDN) [J].
Chin, Tommy, Jr. ;
Mountrouidou, Xenia ;
Li, Xiangyang ;
Xiong, Kaiqi .
2015 IEEE 35TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS (ICDCSW), 2015, :95-99
[6]   Lightweight solutions to counter DDoS attacks in software defined networking [J].
Conti, Mauro ;
Lal, Chhagan ;
Mohammadi, Reza ;
Rawat, Umashankar .
WIRELESS NETWORKS, 2019, 25 (05) :2751-2768
[7]   Discriminating flash crowds from DDoS attacks using efficient thresholding algorithm [J].
David, Jisa ;
Thomas, Ciza .
JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2021, 152 :79-87
[8]   The DDoS attacks detection through machine learning and statistical methods in SDN [J].
Dehkordi, Afsaneh Banitalebi ;
Soltanaghaei, MohammadReza ;
Boroujeni, Farsad Zamani .
JOURNAL OF SUPERCOMPUTING, 2021, 77 (03) :2383-2415
[9]  
Dhawan M., 2015, P NDSS
[10]  
Dong P, 2016, IEEE INT C COMMUNICA, P16